Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 12:33 UTC. Ordered by latest scan.
This is concrete, automatic install-time credential and system-data exfiltration to an unrelated Telegram endpoint. The package should be blocked.
The package performs automatic install-time host and environment reconnaissance followed by external transmission. Its research labeling does not establish consent for this behavior.
This is concrete, unconsented install-time data exfiltration with redundant network channels. The package's research label does not neutralize the automatic behavior.
The automatic lifecycle hooks activate host and environment reconnaissance and transmit the results to an unrelated external Telegram recipient. The behavior is concrete install-time data...