Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 17:33 UTC. Ordered by latest scan.
This is a concrete import-time remote payload execution chain, not telemetry: downloaded bytes are written and executed without validation or user action. The benign-looking exported API...
This is a concrete, hidden import-time remote-code-execution chain unrelated to the advertised feature-toggle API. No install hook is required for the payload to execute once the package...
Direct source inspection confirms reachable import-time download-and-execute behavior with obfuscated infrastructure and no payload integrity verification. The lack of lifecycle hooks doe...
This is concrete import-time remote code execution, not normal module-loader behavior. The unused telemetry-like implementation in lib/telemetry.js reinforces the deceptive payload-loader...