Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 23:35 UTC. Ordered by latest scan.
Direct source inspection confirms automatic install-time credential/environment harvesting and external exfiltration. This is concrete malicious behavior.
This is concrete, repeated exfiltration of local AI-agent conversations triggered by routine use, with no README disclosure or per-launch consent. It is not an install-hook case, but is m...
Direct source inspection confirms an automatic install-time secret-harvesting and exfiltration chain. This is concrete malicious behavior, not a package-aligned network use.
Direct source inspection confirms an automatic install-time credential and wallet-file exfiltration chain. This is concrete malicious behavior, not a noisy static signal.