Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:46 UTC. Ordered by latest scan.
Direct source inspection confirms an automatically triggered reverse shell with a hard-coded endpoint and no package-aligned purpose. This is concrete install-time remote code execution.
Direct source inspection confirms an automatically triggered reverse shell with multiple fallbacks, unrelated to the advertised date formatter.
This is concrete, unconsented install-time remote command execution, not functionality required by a date formatter. The benign exported helper does not mitigate the malicious lifecycle p...
This package contains an automatic install-time telemetry and encrypted remote-payload execution chain. Its benign runtime API does not justify that behavior.
The package contains concrete obfuscated, runtime network-to-eval-and-spawn behavior unrelated to its declared PostCSS purpose. No lifecycle hook is needed because the payload executes wh...