Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:20 UTC. Ordered by latest scan.
The import-time, obfuscated, blockchain-addressed payload retrieval and execution chain is concrete malicious behavior. Absence of an install hook does not mitigate runtime RCE on normal...
This is a concrete import-time staged payload chain with remote code execution, unrelated to the advertised abstraction API. The lack of lifecycle scripts does not mitigate execution on n...
The import-time hidden downloader and detached execution establish concrete malicious behavior despite the absence of npm lifecycle hooks. The bundled telemetry file contains similar load...
This is concrete import-time remote payload execution, unrelated to the declared timeline API. The unused telemetry module contains a parallel downloader/executor implementation, reinforc...