Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 02:37 UTC. Ordered by latest scan.
The preinstall chain is unrelated to an ESLint config and concretely executes an obfuscated credential-focused remote-code payload. This is malicious install-time behavior.
This is not aligned with an ESLint configuration package: its preinstall loader executes a large obfuscated token-harvesting payload. The benign exported configs do not mitigate the insta...
The install hook executes an obfuscated, network-capable payload rather than package-aligned configuration code. Its remote eval and token-handling behavior establish malicious intent.
The preinstall lifecycle executes an obfuscated payload with remote eval and credential-related behavior, unrelated to the advertised repository-config function. This is concrete maliciou...