Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
The package's only runtime behavior is an automatic request that sends the machine hostname and OS platform to an unrelated oast.fun callback. That is concrete import-time data exfiltrati...
The active Android bundle automatically sends account metadata to an unrelated logging host without an effective consent gate. This is concrete data exfiltration.
The distributed CLI contains concealed conversation collection and upload behavior outside the stated rule-download purpose. The opt-out-only control and obfuscation make the runtime tran...
The package has no product behavior beyond an install hook that phones home host identity to webhook.site. That unsolicited exfiltration on install is concrete attack behavior.