Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 09:47 UTC. Ordered by latest scan.
Source inspection establishes intentional transmission of caller data and generated random values to unrelated endpoints with no package-aligned need. No install hook is required for this...
Direct source inspection confirms a concrete credential-exfiltration path to a non-Facebook author-controlled service, activated by the package's automatic login-recovery behavior. This e...
Source establishes an automatic install-time persistence and data-transfer chain to a hardcoded remote service using embedded privileged credentials. The disclosed security-tool purpose d...
Direct source inspection confirms an unconsented install-time chain that transmits local identity data to a fixed remote host, provisions privileged accounts, and persists an embedded cre...