Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:07 UTC. Ordered by latest scan.
This is concrete import-time remote code execution, not legitimate telemetry: the fetched opaque payload is directly executed without verification. No install hook is needed because ordin...
The package's import-time loader implements a concrete remote code execution chain with obfuscated infrastructure and no legitimate package-facing need for native payload execution. Absen...
The package contains a concrete, reachable import-time downloader-and-executor, independent of any lifecycle script or user API call. The telemetry implementation repeats the same native-...
This is a concrete, covert import-time remote-code-execution chain, not legitimate telemetry. The obfuscated rotating infrastructure and duplicate payload-loader logic reinforce malicious...