Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 18:55 UTC. Ordered by latest scan.
The package's stated API does not require a native executable, yet import-time code silently downloads and executes one with no meaningful integrity verification. The remote payload sourc...
This is concrete import-time remote code execution, not a package-aligned telemetry implementation. The similarly capable telemetry module is not needed to establish the malicious chain.
This is concrete unconsented remote native payload execution on normal package import, not legitimate telemetry. The lack of lifecycle hooks does not mitigate the reachable import-time ex...
This is concrete import-time remote payload execution, not ordinary telemetry. The loader is concealed behind a benign entrypoint and uses multiple remote fallback channels.