Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 22:08 UTC. Ordered by latest scan.
This is a concrete import-time staged-payload execution chain, not ordinary telemetry: unverified remote bytes are silently executed detached. The package has no lifecycle hook, but norma...
This is a concrete import-time remote payload execution chain unrelated to the claimed fixture module. Absence of npm lifecycle scripts does not mitigate runtime compromise upon import.
This is a concrete import-time staged payload loader and remote executor, unrelated to the advertised claims-domain API. The absence of install hooks does not reduce the runtime RCE expos...
The concrete import-time remote payload download and detached execution are malicious behavior, not package-aligned SDK functionality. Absence of lifecycle hooks does not mitigate the rea...