Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
The package has a concrete automatic postinstall exfiltration path to an unrelated webhook endpoint. The collected host and user metadata is sent without user interaction or package-align...
The package has an automatic postinstall beacon that exfiltrates local system and project metadata to a third-party endpoint. This is concrete malicious install-time data collection.
This is concrete, automatic install-time credential and system-data exfiltration to an unrelated Telegram endpoint. The package should be blocked.
The package performs automatic install-time host and environment reconnaissance followed by external transmission. Its research labeling does not establish consent for this behavior.