Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:40 UTC. Ordered by latest scan.
The import-time loader is concrete, stealthy remote binary execution unrelated to the stated session-management purpose. The lack of npm lifecycle hooks does not mitigate execution when c...
This is a concrete import-time remote payload execution chain unrelated to the advertised linting package. The absence of lifecycle hooks does not mitigate execution when consumers load t...
This is a concrete import-time staged payload chain with remote code execution, unrelated to the advertised abstraction API. The lack of lifecycle scripts does not mitigate execution on n...
The import-time hidden downloader and detached execution establish concrete malicious behavior despite the absence of npm lifecycle hooks. The bundled telemetry file contains similar load...