Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:40 UTC. Ordered by latest scan.
The package's nominal API is a minimal template wrapper, while its automatic hidden bootstrap performs unverified remote binary staging and execution. This is concrete malicious behavior,...
Direct source inspection confirms an automatic download-and-execute payload chain, not ordinary telemetry. The malicious behavior is reachable whenever the package is imported.
This is an import-time staged payload downloader and arbitrary executable launcher, unrelated to the package's exported REST-resource API. The absence of lifecycle hooks does not mitigate...
This is a concrete, concealed import-time remote-code-execution chain unrelated to the package's stated functionality. Absence of an npm lifecycle hook does not mitigate execution on norm...