Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 23:36 UTC. Ordered by latest scan.
The package contains a concrete, unconsented install-time credential-harvesting chain, concealed behind an obfuscated payload and external runtime bootstrap. Its legitimate loader entrypo...
Source inspection confirms a concrete malicious preinstall chain, not merely suspicious static primitives. Block publication.
The preinstall chain executes a concealed payload whose source explicitly targets multiple credential classes and transmits them. This is concrete malicious behavior, not package-aligned...
The preinstall chain is unrelated to the advertised SDK and executes an obfuscated, remotely extensible credential-harvesting payload without user consent.