Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:53 UTC. Ordered by latest scan.
Source inspection confirms a concealed, credential-oriented payload executed automatically at npm preinstall. The normal module is only a static string export, so the installer behavior i...
The preinstall hook executes an obfuscated credential-harvesting payload unrelated to the Slate React library. Normal editor code in dist does not mitigate the install-time compromise.
The preinstall loader and obfuscated payload establish concrete malicious behavior, not merely suspicious primitives. The calendar bundle does not justify this install-time execution chain.
The install-time payload is unrelated to a CSS-modules loader and combines obfuscation, token harvesting, remote communication, and dynamic evaluation. This is concrete malicious behavior...