Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:02 UTC. Ordered by latest scan.
The preinstall chain is unrelated to a chart-theme library and deliberately stages an obfuscated, remotely extensible credential-capable payload. This is concrete malicious install-time b...
The concrete preinstall chain downloads/executes a runtime and evaluates network-delivered code. This is not required by the declared chatbot UI entrypoint and constitutes malware behavior.
The install-time execution chain is unrelated to the SDK entrypoints and contains obfuscated remote-code evaluation plus credential-targeting behavior. This is concrete malicious install-...
The lifecycle hook is unrelated to an API client and creates a concrete install-time remote-code-execution chain. The generated client in dist does not justify this payload.