Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 06:26 UTC. Ordered by latest scan.
Direct source inspection confirms a concrete, runtime-reachable credential disclosure path through a hidden global administrator. The absence of lifecycle hooks does not mitigate the back...
Bundled operational OAuth credentials create a concrete, implicit data-routing path from user files to a third-party account. The absence of install hooks does not mitigate this user-trig...
Direct source inspection confirms an undisclosed, foreign privileged account can retrieve credentials from every consumer deployment. This is a concrete credential-theft control path, not...
The package has no install-time execution, but its documented runtime flow collects sensitive refresh tokens and sends them to a backend controlled outside the consumer's infrastructure w...