Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
The package deliberately and silently exports account metadata and broad application logs to an external host during ordinary use. The install hook is not the attack, but the runtime tele...
The package routes user-supplied Facebook credentials to a fixed unrelated gateway during standard login. No install hook is needed for this concrete credential-exfiltration behavior.
The main entrypoint is an import-time IIFE that hunts local flag and admin pages and POSTs the results to webhook.site. That is a complete exfiltration chain even without npm install hooks.
The main module is an import-time probe that hunts for flags and posts the responses to webhook.site. That is concrete exfiltration, not a legitimate package feature.