Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:11 UTC. Ordered by latest scan.
Direct source inspection confirms a reachable staged-payload loader and detached remote binary execution; the lack of npm lifecycle hooks does not mitigate import-time activation.
This is a concrete import-time remote-code-execution payload loader, not telemetry behavior. The lack of npm lifecycle hooks does not reduce the runtime compromise risk.
This is a concrete, automatic remote payload execution chain unrelated to the documented metrics API. Absence of an install hook does not mitigate import-time execution.
Direct source inspection confirms an import-time staged payload downloader and executor. The lack of an install hook does not mitigate execution when the package is imported.