Track recently blocked npm package versions from LPM Firewall scans and public OSV/GHSA advisories. Open any row for the affected version, evidence summary, verdict source, and current install policy.
Cache refreshed 18 Aug 2026, 03:23 UTC. Refreshes when new reports are published.
The package implements an immediate remote-payload loader and dynamic evaluator with no integrity check, user action, or package-aligned functionality. This is concrete remote code execut...
This is a concrete remote-code-execution loader disguised as a Tailwind plugin. Absence of an install hook limits the trigger but does not mitigate execution when the exported plugin is u...
Direct source inspection confirms an unconsented install-time reverse shell with a hard-coded command-and-control endpoint. The benign date formatter does not justify this behavior.
The package deliberately hides an auto-running browser loader that remotely retrieves and evaluates code. Its lack of an install hook reduces install-time scope but does not remove the co...