Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:57 UTC. Ordered by latest scan.
The install-time execution chain launches an obfuscated payload with remote eval and credential-exfiltration behavior. This is concrete malicious behavior, not an SDK runtime feature.
The install-time execution chain runs an unrelated, heavily obfuscated payload with credential-focused and remote-code capabilities. This is concrete malicious behavior, not a package-ali...
Concrete install-time execution of an obfuscated credential-harvesting payload establishes malicious behavior. The legitimate-looking UI bundles do not mitigate the preinstall attack path.
The benign lint-rule entrypoint does not justify the preinstall bootstrap or its obfuscated token-oriented payload. This is concrete malicious install-time behavior.