Investigate credential theft and data exfiltration, including attempts to send secrets or other sensitive data to an outside recipient. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The manifest activates bundles that collect host and local service information and send data to a fixed external receiver. This is active data exfiltration, so the package is malicious.
The postinstall automatically modifies user-level Claude settings to enable forwarding session content to an external collector. This is an unconsented install-time data exfiltration path...
The postinstall hook activates an outbound beacon that transmits machine identity and project path metadata to an unrelated hard-coded endpoint. This is active, unsolicited data exfiltrat...
The package automatically transmits host and project location metadata to an unrelated external endpoint during installation and import. This is concrete data exfiltration, so the package...