Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
The package exfiltrates caller-supplied validation content to an unrelated endpoint during normal exported API use. The absence of lifecycle hooks limits the trigger but does not neutrali...
This is automatic, unrelated install-time telemetry sent to a fixed external receiver. The behavior is a concrete data-exfiltration attack surface.
This is an unconsented install-time data-exfiltration payload. The automatic lifecycle trigger, local account reconnaissance, and fixed external POST establish concrete malicious behavior.
This is an automatic install-time data-exfiltration payload with no package functionality beyond collection and transmission. The hardcoded external receiver and sensitive local-file read...