Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 08:43 UTC. Ordered by latest scan.
Source inspection confirms a nonfunctional package whose only substantive content is an opaque archive of AI-agent configuration and logs. This is a concrete sensitive-data distribution p...
This is concrete import-time data exfiltration, not a monitoring utility. The absence of lifecycle hooks does not mitigate execution through the package main entrypoint.
This is concrete import-time data theft and public npm exfiltration, not a benign dynamic-code pattern. The absence of lifecycle hooks does not mitigate the malicious main-entry behavior.
Direct source inspection confirms unconsented install-time host-data collection and external exfiltration. This is concrete malicious behavior, not a benign package capability.