Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 22:28 UTC. Ordered by latest scan.
Confirmed source establishes a concrete, silent remote-payload execution chain reachable from the package entrypoint. The lack of install hooks does not mitigate runtime compromise on imp...
The package contains concrete import-time download-and-execute behavior, not merely telemetry primitives. The lack of install hooks does not mitigate execution when a consumer imports the...
This is confirmed import-time remote payload execution, not legitimate telemetry. The lack of an npm lifecycle hook does not mitigate execution when consumers import the package.
This is a concrete, import-time remote-code-execution chain with opaque payload delivery and stealth-oriented error suppression. The lack of an npm lifecycle hook does not mitigate runtim...