Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 07:15 UTC. Ordered by latest scan.
Source establishes a concrete surveillance-and-exfiltration chain paired with stealth persistence and proctoring evasion. The benign postinstall hook does not mitigate the malicious runti...
The package contains concrete, automatic install-time credential theft and remote exfiltration behavior, with additional cloud-database probing. Its research label does not remove the unc...
This is a concrete unconsented install-time credential-exfiltration and cloud-access chain, not merely suspicious primitives. Research-oriented comments do not mitigate automatic executio...
Source code establishes an active, silent credential/configuration exfiltration path to an unrelated remote host. Package-local lifecycle wiring and the opt-in MCP bridge do not mitigate...