Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 02:27 UTC. Refreshes when new reports are published.
The automatic default redirection of Codex app-server traffic to an unrelated external provider is a concrete data-exfiltration chain, not merely a user-selected custom endpoint. The post...
This is concrete runtime data exfiltration, not merely a capability library: clipboard transmission starts automatically when the CLI runs. The absence of an install hook limits install-t...
Runtime execution automatically exfiltrates arbitrary clipboard changes to a remote endpoint and provides screenshot upload through a stealth interface. The absence of lifecycle hooks lim...
This is an unconsented install-time collection and exfiltration chain targeting the consuming project's .env, with an intentionally hidden destination and silent failure handling.
The source directly constructs a set of environment-secret values and uploads it automatically to a fixed external host. This is credential exfiltration, irrespective of the absence of in...