Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 22:44 UTC. Ordered by latest scan.
This is concrete install-time execution of an obfuscated payload that targets GitHub credentials, unrelated to the published charting library. The explicit bootstrapper and payload form a...
The lifecycle chain provides concrete unconsented install-time execution of an obfuscated credential-harvesting and exfiltration payload. This is malicious, not a package-aligned dependen...
The benign title component is accompanied by an unrelated, obfuscated preinstall payload that downloads a runtime and supports remote eval and token access. This is concrete malicious ins...
The install hook is unrelated to an ESLint configuration package and launches a concealed credential-oriented payload. This is concrete malicious behavior, not a noisy static match.