Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 15:19 UTC. Ordered by latest scan.
The published CommonJS entrypoint contains a concealed, hash-gated payload launcher with detached child-process execution. The lack of lifecycle hooks does not mitigate runtime execution...
This is a concrete staged remote-code-execution chain hidden behind a transaction-data API. The absence of lifecycle hooks does not mitigate runtime execution after an ordinary library call.
The lifecycle behavior is concrete and active by default, not merely a user-invoked CLI feature. It downloads and executes remote scripts during installation, so the package warrants bloc...
This is a concrete remote-code-execution loader, not a benign dynamic evaluation pattern. It is runtime-triggered rather than install-time, but warrants blocking because an untrusted remo...