Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
This package uses automatic install hooks to exfiltrate local environment metadata to an external service. That is concrete unconsented install-time data collection.
This is concrete user-triggered bulk file exfiltration to a source-controlled Telegram destination, inconsistent with the package identity. The absence of an install hook does not remove...
The package contains an exported runtime path that exfiltrates supplied phone numbers to an unrelated host with a deliberately abusive header. Although not automatic, this is concrete mal...
The package contains a concrete, exposed phone-number exfiltration path to an unrelated host with an abusive custom header. Its benign version-check preinstall hook does not mitigate that...