Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 05:34 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented install-time collection and external transmission of host data. This is concrete malicious behavior, not merely a suspicious primitive.
Direct source inspection confirms an install-time host-fingerprinting and external exfiltration chain. The nested archive contains the same package source and does not mitigate this behav...
Direct source inspection confirms unconsented install-time host fingerprint exfiltration. This is concrete malicious behavior, not an inert test artifact.
Direct source inspection confirms unconsented install-time host fingerprint exfiltration. The nested archive contains the same manifest and source pattern.