Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 12:31 UTC. Ordered by latest scan.
Source inspection confirms an install-time obfuscated script that transmits the full environment, creating a concrete credential-exfiltration risk. The behavior is not package-aligned tel...
Source inspection confirms automatic install-time collection and outbound transmission of process.env, which can contain credentials and is not necessary for a dotenv-style package. The p...
Direct source inspection shows concrete install-time credential/environment collection and obfuscated outbound telemetry behavior. Because it runs automatically during npm install and col...
Source inspection confirms concrete runtime exfiltration of process.env to an unrelated endpoint in both TypeScript source and published dist entrypoints. The lifecycle scripts are noisy...