Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:19 UTC. Ordered by latest scan.
The package’s declared certificate API is unrelated to its import-time downloader/launcher. No lifecycle hook is needed because requiring the main entrypoint triggers the malicious chain.
Confirmed import-time staged payload download and detached execution is concrete malicious behavior, regardless of the absence of npm lifecycle hooks.
This is a concrete import-time remote code-execution chain, not ordinary telemetry: arbitrary remote bytes are executed without integrity verification or user invocation. The lack of inst...
This is a concrete import-time remote payload execution chain unrelated to the advertised adapter. No install hook is needed because requiring the normal entrypoint triggers it.