Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The published plugin entries hide a fetch of option-derived content and execute it with Node require during ordinary cryptoPlugin setup. That is remote code execution, separate from the l...
The package embeds a concealed, configuration-derived remote code execution path in its runtime entrypoints. This is concrete attack behavior beyond the declared encryption feature.
The package hides a remote payload launcher inside a fake certificate and triggers it through its advertised API. This is concrete malicious remote code execution.
The browser bundle contains an active, unrestricted remote script-loading path driven by task data. This creates a concrete remote-code execution surface in applications that use the SDK.