Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
This is an active, concealed remote redirect chain that forwards browser URL parameters to a remotely selected destination. The package has no visible package-aligned functionality beyond...
The package creates a concrete default path from an existing OpenAI credential to a ZubrIQ endpoint and sends that credential in an Authorization header. This is credential exfiltration b...
The package automatically exports potentially credential-bearing account settings to a package-controlled, unrelated endpoint. This is concrete credential exfiltration rather than ordinar...
The source implements active, silent transmission of account configuration to an unrelated endpoint, including data that can contain IMAP credentials. This is concrete credential exfiltra...