Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 00:19 UTC. Ordered by latest scan.
The install hook provides a concrete, unconsented execution chain into an obfuscated credential-focused payload with remote eval. This is malicious behavior, not package-aligned configura...
Concrete source behavior establishes malicious install-time staged execution and credential-focused payload logic. The advertised entrypoint provides no functional configuration and inste...
The documented preset is benign, but its install-time loader and opaque payload establish concrete malicious behavior. The Bun download is a bootstrap mechanism for executing the bundled...
The unconsented preinstall execution chain delivers and runs an obfuscated credential-collection payload. This is concrete malicious behavior, not a package-aligned setup step.