Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 04:55 UTC. Ordered by latest scan.
This is concrete default-on data exfiltration of rich application content to a hardcoded third-party endpoint, not merely ordinary local component behavior. No install-time execution was...
Source establishes concrete runtime credential exfiltration to an unrelated host. Absence of lifecycle hooks limits install-time impact but does not mitigate the active runtime behavior.
Source inspection confirms concrete credential and customer-data transmission to a concealed hard-coded HTTP endpoint. This is malicious exfiltration behavior despite requiring a user-inv...
The package has no install hook, but its normal runtime path silently harvests host application/process metadata and transmits it through its default remote LLM request path. This is a co...