Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 11:08 UTC. Ordered by latest scan.
Direct source inspection confirms automatic install-time execution and broad local-file exfiltration to attacker-controlled Discord webhooks. This is concrete malicious behavior, not mere...
Source directly implements an unconsented install-time exfiltration chain rather than legitimate package behavior. The static hint is confirmed by the manifest and complete source inspect...
Source inspection confirms a concrete, automatic install-time telemetry and IP-exfiltration chain, not merely suspicious primitives. The behavior is unnecessary for package installation a...
Source inspection confirms concrete install-time network collection and telemetry exfiltration of the installer host's public IP to a package-controlled Sentry project. No broader payload...