Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:02 UTC. Ordered by latest scan.
Confirmed source behavior is an import-triggered remote binary downloader and executor, not package-aligned telemetry. The unused/parallel telemetry implementation repeats the same payloa...
The package’s documented wrapper has no legitimate need to execute opaque remote binaries on import. The behavior is concrete, automatic, stealthy, and provides remote code execution.
The package contains a concrete, stealthy import-time downloader and executor of remote native payloads. The absence of an npm lifecycle hook does not mitigate runtime compromise when con...
This is a concrete import-time remote-code-execution chain unrelated to the advertised UI package. The absence of lifecycle hooks does not mitigate execution when consumers import the pac...