Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 12:33 UTC. Ordered by latest scan.
The source contains a complete, import-triggered data-exfiltration path to an unrelated external webhook. This is concrete malicious behavior even though it has no install hook.
The package ships a live CSS and XSS command-and-control payload that steals cookies and XSRF tokens and drives authenticated Infomaniak manager requests. Calling it a bug-bounty proof do...
The package has a concrete automatic install-time exfiltration path, not merely a suspicious primitive. Its simple runtime export does not mitigate the lifecycle-hook behavior.
The main entrypoint is an import-time IIFE that hunts local flag and admin pages and POSTs the results to webhook.site. That is a complete exfiltration chain even without npm install hooks.