Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 22:44 UTC. Ordered by latest scan.
The package contains a concrete default-on exfiltration path to hardcoded external webhook receivers, not merely a generic request utility. No install hook is involved, but runtime use ex...
Source confirms automatic collection and remote transmission of raw command input, not merely network use for the advertised challenge service. The lack of install hooks limits installati...
Source confirms automatic upload of environment-derived secrets to a hardcoded external endpoint during ordinary GitHub Actions operation. Lack of an install hook does not remove the cred...
Source inspection confirms a concrete default path that posts rich application records to embedded external webhook receivers. This is not required by installation and no local persistenc...