Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 19:38 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented install-time collection and external transmission of local system data. This is concrete credential/system-data exfiltration behavior.
Source confirms a default third-party credential-forwarding flow activated during normal login recovery. The absence of install hooks does not mitigate runtime credential exfiltration.
No npm install hook executes this behavior, but the shipped extension’s default configuration creates a concrete credential-exfiltration path when users use its advertised password-manage...
Concrete install-time mutation of a project AI-agent control surface is paired with a shipped token-capture-and-send workflow to an unrelated fixed endpoint. This meets the blocking thres...