Investigate persistence and destructive actions, including unwanted lasting changes, damaged files, and disrupted systems. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
Concrete postinstall behavior creates a hidden privileged remote-access path and weakens RDP security. This exceeds a benign installer’s expected scope and is executed automatically on in...
The install hook performs unrelated host-data collection, external-path mutation, and detached-process creation without user consent. These concrete install-time behaviors warrant blockin...
Source directly confirms an automatic elevated postinstall chain that creates hidden privileged RDP access and weakens RDP security. Lack of exfiltration does not mitigate the concrete re...
Direct source inspection confirms unconsented install-time mutation of a consumer CI control surface and a persistent external reporting path. The browser bundle's Firebase traffic does n...