Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:54 UTC. Ordered by latest scan.
Source directly establishes a runtime credential-exfiltration path to rmf39.aaz.lt. The lack of install hooks does not mitigate this user-runtime attack.
The install-time source contains a concrete credential-exfiltration chain; the advertised arithmetic functionality does not justify it.
Concrete silent transmission of account metadata to an unrelated logging endpoint establishes unconsented data exfiltration. The install hook itself is benign, but does not mitigate the r...
The package has no declared functionality beyond an automatic preinstall script that covertly sends local host metadata over DNS. This is concrete, unconsented install-time data exfiltrat...