Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
The manifest contains a concrete automatic postinstall exfiltration command. Its environment collection and remote transmission are malicious regardless of the absent main entrypoint.
The package has a concrete, intentional host-identity exfiltration path when its CLI or main entrypoint runs. Lack of an install hook limits the trigger but does not make the behavior ben...
The package implements undisclosed host-identity exfiltration to an unrelated endpoint on command execution. Although it has no install hook, this is concrete malicious behavior.
This package performs concrete, undisclosed host identity exfiltration whenever its entry point runs. The absence of an install hook does not neutralize the malicious runtime behavior.