Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:57 UTC. Ordered by latest scan.
Source directly establishes a default external credential receiver and sends authentication material to it during normal login. No lifecycle hook is needed for this concrete runtime crede...
Source inspection confirms hard-coded third-party uploads of project files and system identity data, including config files that the CLI treats as credential-bearing. The postinstall scaf...
Concrete default-enabled runtime data exfiltration is present in source; the absence of an install hook does not mitigate it.
Runtime behavior establishes concrete credential exfiltration to a package-supplied remote datastore; it is not required for a local WhatsApp bot. The preinstall hook is unrelated and doe...
Direct source inspection confirms unconsented install-time collection and external transmission of local system data. This is concrete credential/system-data exfiltration behavior.