Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 17:33 UTC. Ordered by latest scan.
Source establishes import-time child-process launch followed by obfuscated network retrieval and dynamic execution. Absence of lifecycle hooks does not mitigate this runtime backdoor.
The source establishes an immediate remote-payload execution chain; no legitimate package functionality is present to justify it.
Source inspection confirms an unverified, environment-configurable payload loader executed during postinstall. The shipped public module does not implement the README's TWAP functionality...
This is an unconsented install-time remote-code-execution chain. The package contains no local installer payload to inspect or integrity control for the script it executes.