Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 16:45 UTC. Ordered by latest scan.
This package has a reachable import-time unsigned remote-payload execution chain. The absence of lifecycle hooks does not mitigate execution when consumers import the package.
The documented foundational module has no legitimate connection to an import-time remote native-payload loader. The behavior is concrete, automatically reachable, and enables arbitrary co...
This is an import-time staged payload loader with remote binary execution, not legitimate telemetry. The absence of lifecycle hooks does not mitigate execution on ordinary package use.
This is concrete import-time remote payload execution, not legitimate utility behavior. The lack of an npm lifecycle hook does not mitigate runtime execution on require.