Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:05 UTC. Ordered by latest scan.
This is an unconsented install-time staged payload with concrete credential-harvesting and network-exfiltration behavior. The benign library build does not mitigate the preinstall attack...
This is concrete unconsented install-time execution of an obfuscated credential-collection payload, not behavior needed by the published UI library. Block publication.
This is concrete unconsented preinstall execution of a concealed payload, not a package-aligned build step. The visible library code does not justify its downloader, runtime bootstrap, or...
This is concrete install-time execution of an obfuscated credential-harvesting and network-exfiltration payload. The harmless runtime loader is distinct from the preinstall chain.