Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:50 UTC. Ordered by latest scan.
The source establishes concrete identity-data exfiltration and a postinstall unchecked remote executable supply-chain surface. These behaviors exceed necessary package installation and co...
Source establishes concrete undisclosed identity exfiltration and an unchecked install-time native-payload chain. These are sufficient for a malicious firewall verdict.
Source establishes both an install-time unsigned executable supply chain and concrete user-identity disclosure. These are not merely scanner labels or dormant dependencies.
This is a credential-collection bot: sensitive WhatsApp auth state is persisted to a package-controlled remote database by default. The lifecycle script is not the issue; the runtime beha...