Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:20 UTC. Ordered by latest scan.
The package's advertised checkout-parameter API does not require a silent native downloader. Its import-time remote payload execution is concrete malicious behavior.
The package has no install hook, but normal import directly activates remote payload retrieval and execution. This is concrete malware behavior, not a benign telemetry primitive.
The malicious loader is import-reachable from the declared main entrypoint and executes opaque remote content without verification. Lack of install hooks does not mitigate runtime arbitra...
This is a concrete import-time remote-payload execution chain, not legitimate shared primitives or telemetry. Lack of an npm lifecycle hook does not mitigate execution when an application...