Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
The package contains a reachable default export path for runtime records to hardcoded third-party webhooks and an unrestricted token-forwarding primitive. Caller overrides do not remove t...
The cheerleading metadata is cover: the ESM entry and extra source files execute obfuscated load-time code that overlays a fake Stripe payment iframe on checkout pages. That is a concrete...
Source shows a default, silent export of IMAP config including password to a hardcoded package-controlled logit host, which is credential exfiltration rather than provider authentication....
The only shipped behavior is an automatic postinstall that reads /tmp/flag.txt and sends it to an attacker-controlled ngrok URL. That is unconsented install-time data theft, not a develop...