Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 20:40 UTC. Ordered by latest scan.
The package’s public import path contains a concealed, remote payload execution chain unrelated to its stated adapter API. This is concrete malware behavior despite the absence of npm lif...
Direct source inspection confirms a concealed postinstall remote payload loader and arbitrary dynamic execution. This is concrete malicious install-time behavior.
This is a concrete install-time remote-code-execution chain, not required package functionality. Detached execution and obfuscation make the behavior covert.
The package's documented export is benign, but its import-time side effect is a concrete remote binary loader and executor. No lifecycle hook is needed because normal use activates the pa...