Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:16 UTC. Ordered by latest scan.
This is concrete import-time remote-code execution unrelated to the advertised button component. The absence of install hooks does not mitigate the automatic runtime trigger.
This is a concrete import-time remote payload execution chain, not ordinary telemetry. The package has no install hook, but its normal entrypoint still activates the downloader and launcher.
This is concrete, import-time staged remote-code execution with no legitimate functionality exposed by the package that requires it. The absence of lifecycle hooks does not mitigate runti...
This is concrete import-time remote payload execution, not package-aligned telemetry. The absence of npm lifecycle hooks does not mitigate the reachable malicious entrypoint.