Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:34 UTC. Ordered by latest scan.
Source inspection confirms a lifecycle-triggered download-and-execute chain, not merely suspicious primitives. Opt-out environment flags do not make the default unprompted behavior safe.
The package deliberately performs an unconsented, silent import-time installation of a differently named registry package in the consumer project. This is a concrete supply-chain executio...
This is a concrete staged remote-code-execution chain, not merely a networking or evaluation primitive. Lack of an install hook limits the trigger but does not remove the malicious runtim...
Source confirms unconsented install-time remote payload execution and external AI CLI installation. The explicit opt-outs and isolated default config do not mitigate code execution before...