Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 03:21 UTC. Ordered by latest scan.
The third-party credential submission is enabled by the default API-server setting and reached by the package's automatic recovery path. No install hook is needed for this runtime credent...
Source establishes a reachable, default-enabled credential-exfiltration path with no redaction. Absence of lifecycle hooks does not mitigate runtime export of authentication secrets.
Source confirms reachable, automatic reporting to hardcoded third-party Telegram recipients during normal CLI use. This is concrete unauthorized data exfiltration, not merely a noisy netw...
Source confirms automatic third-party telemetry containing account data and serialized IMAP settings, including password fields. The benign workspace-only postinstall hook does not mitiga...