Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 06:19 UTC. Ordered by latest scan.
The package contains a concrete, automatic credential-bearing data flow to an unrelated remote logging endpoint. This is malicious exfiltration, not required mail-provider traffic.
The package contains no install-time behavior, but its normal runtime path automatically exfiltrates mail-account metadata through a third-party logging endpoint. The source directly esta...
The package contains a concrete, automatic, non-package-aligned host-fingerprinting exfiltration chain at install time. The normal SDK entrypoint does not justify this hidden telemetry.
This is concrete, unconsented install-time reconnaissance and exfiltration unrelated to the advertised GraphQL generator.