Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 11:26 UTC. Ordered by latest scan.
Direct source inspection confirms unconsented install-time reconnaissance and exfiltration to a hard-coded external endpoint. The benign main library does not justify the lifecycle hook b...
Source inspection confirms concrete install-time credential and environment exfiltration unrelated to the package's date utility purpose. The package should be blocked.
The lifecycle hook performs concrete unconsented data exfiltration to an external callback domain, using multiple fallback network tools. The benign date formatting entrypoint does not ju...
Direct source inspection confirms unconsented install-time collection and external exfiltration of local environment data. This is concrete malicious behavior rather than package-aligned...