Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 20:14 UTC. Ordered by latest scan.
This is a concrete import-time remote payload execution chain unrelated to the documented abstraction API. The lack of lifecycle hooks does not mitigate execution on ordinary package import.
The package's main entrypoint performs import-time download-and-execute behavior unrelated to its stated reactive-store purpose. No lifecycle hook is needed because ordinary package use t...
This is concrete import-time remote code execution, not package-aligned telemetry. No lifecycle hook is needed because requiring the declared main entrypoint activates the loader.
This is a concrete import-time staged-payload execution chain unrelated to a navigation router. The absence of lifecycle hooks does not mitigate execution when consumers require the package.