Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 19:28 UTC. Ordered by latest scan.
The entrypoint reaches an unsigned remote payload downloader/executor during normal import, unrelated to the stated React-component purpose. The unused telemetry module contains a similar...
This is a concrete import-time remote binary download-and-execute chain unrelated to the claimed UI toolkit. Absence of an npm lifecycle hook does not mitigate execution on ordinary packa...
The package’s normal import path implements an unconsented staged payload downloader and executor. This is malicious regardless of the absence of npm lifecycle scripts.
Direct source inspection confirms an import-triggered download-and-execute chain. The lack of install hooks does not mitigate arbitrary code execution when consumers import the package.