Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 23:51 UTC. Ordered by latest scan.
This is a concrete, import-time remote payload execution chain unrelated to the package's stated minimal API. The lack of lifecycle scripts does not mitigate execution when consumers impo...
This is concrete import-time remote payload execution, not normal telemetry. No installation hook is needed because any consumer runtime import triggers it.
The package's declared EventBus/test-fixture purpose does not justify an import-time remote binary loader. The concrete download-and-execute chain establishes malicious behavior.
Source inspection confirms an import-time downloader and detached payload launcher, not just suspicious primitives. The absence of lifecycle hooks does not mitigate execution on normal im...