Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 10:05 UTC. Ordered by latest scan.
Source inspection confirms unconsented install-time secret harvesting and external exfiltration in postinstall.js. This is concrete malicious behavior, not package-aligned SDK functionality.
The provided scanner snippets indicate concrete install-time exfiltration behavior, but finalization requires direct source inspection and this environment did not permit further tool use...
Direct source inspection confirms unconsented install-time credential harvesting and external exfiltration unrelated to an SDK. This is concrete malicious behavior, not merely a suspiciou...
Direct source inspection confirms unconsented install-time credential and file harvesting with external exfiltration to Telegram, unrelated to an OpenSea SDK. This is concrete malicious b...