Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 00:22 UTC. Ordered by latest scan.
This is an import-time staged remote-code-execution loader unrelated to the declared UI-component package. The absent lifecycle hook does not mitigate automatic execution when consumers i...
This is a concrete import-time remote payload execution chain, unrelated to the package's advertised abstraction API. No install hook is required for compromise once a consumer imports it.
This is an import-time staged payload loader with remote binary execution, unrelated to the documented minimal adapter API. No lifecycle hook is needed because requiring the package activ...
This is a concrete import-time remote payload execution chain, not ordinary telemetry. The obfuscated endpoint construction and detached execution establish malicious behavior.