Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 21:42 UTC. Ordered by latest scan.
The package contains concrete, reachable remote payload execution on import. The absence of an install hook does not mitigate this runtime compromise.
This is a concrete import-time remote-code-execution chain unrelated to the minimal exported SDK. The absence of npm lifecycle hooks does not mitigate runtime execution on ordinary use.
This package contains an import-time, unsigned remote binary loader and detached executor unrelated to its minimal stated client API. The concrete execution chain is sufficient for a bloc...
The package's normal import path provides an immediate, unverified download-and-execute capability. Obfuscated endpoint construction, DNS payload fallback, and detached execution establis...