Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 02:37 UTC. Ordered by latest scan.
The package has a concrete credential-exfiltration path and runtime mutation of a foreign AI-agent control surface. Its harmless postinstall does not mitigate those activated runtime beha...
Concrete install-time host/user metadata exfiltration is present in source and is unrelated to the package's advertised utility. This warrants blocking publication.
The automatic external transmission of account configuration, including potentially credentials, is concrete malicious behavior. Benign workspace linking at install does not mitigate that...
Direct source inspection confirms an install-time shell command that collects and exfiltrates host/user identifiers to a third party. The runtime utility entrypoint does not justify this...