Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
The package uses automatic install hooks to transmit host-identifying information to unrelated fixed external endpoints. This is concrete malicious data exfiltration behavior.
Automatic lifecycle hooks actively beacon local system metadata to fixed external endpoints. The behavior is concrete install-time data exfiltration, not normal package functionality.
This is concrete, automatic install-time collection and external transmission of host data. The behavior is not needed for the declared package and constitutes malicious data exfiltration.
This is an active, obfuscated browser redirect and visitor-data forwarding payload with no stated package functionality. It is not normal npm package behavior and conceals its remote dest...