Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 09:34 UTC. Ordered by latest scan.
index.js is a reverse-shell dropper on the published main export, with check.js and CI invoking it. That is concrete remote code execution, not dual-use tooling.
Importing the package runs a packed dropper that collects host identity, talks over axios, and executes decoded code with Function and execSync. The Pino-looking docs and empty middleware...
This is a concrete import-triggered remote code execution and persistence mechanism, not a package-aligned utility. The absence of an install hook does not mitigate execution on ordinary...
src/index.js is an obfuscated Ethereum-backed dropper that evals and spawn-executes recovered code on plugin import, while the README, types, and repository metadata impersonate a Tailwin...