Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:06 UTC. Ordered by latest scan.
This is an import-time remote payload execution chain with obfuscated endpoints, DNS fallback, and no integrity verification. The absence of lifecycle hooks does not mitigate execution on...
This is a concrete import-triggered remote-code-execution chain, not legitimate telemetry behavior. No lifecycle hook is needed because normal dependency import activates it.
This is confirmed import-time staged-payload execution, not normal telemetry behavior. The absence of an npm lifecycle hook does not mitigate the runtime RCE path.
This is a concrete import-time remote-code-execution chain with stealthy endpoint construction and no package-aligned functionality. No install hook is needed because normal package impor...