Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 10:45 UTC. Ordered by latest scan.
Source inspection confirms automatic install-time collection and outbound transmission of process.env, which can contain credentials and is not necessary for a dotenv-style package. The p...
Direct source inspection shows concrete install-time credential/environment collection and obfuscated outbound telemetry behavior. Because it runs automatically during npm install and col...
Source inspection confirms concrete runtime exfiltration of process.env to an unrelated endpoint in both TypeScript source and published dist entrypoints. The lifecycle scripts are noisy...
Runtime Sentry reporting can be package-aligned, but executing it automatically from preinstall with a hardcoded DSN and public-IP collection creates concrete unconsented install-time dat...