Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:11 UTC. Ordered by latest scan.
The source directly implements credential theft, remote command execution, C2 communication, and wallet draining; missing declared dependencies may impair execution but do not change its...
Direct source inspection confirms an install-triggered external exfiltration callback. The benign placeholder runtime export does not mitigate the postinstall behavior.
This is concrete credential exfiltration to a non-Facebook package-controlled default endpoint, not merely Messenger API traffic. No install hook is needed because the harmful path is rea...
The hardcoded remote database is active by default and receives WhatsApp credential material during normal runtime. This is concrete credential exfiltration, not merely a noisy scanner ma...