Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 00:46 UTC. Ordered by latest scan.
Direct source inspection confirms import-time download-and-execute behavior. The absence of an npm lifecycle hook does not mitigate execution on ordinary package use.
The documented telemetry claim is inconsistent with the import-time download-and-execute behavior. No lifecycle hook is needed because ordinary package import activates the payload chain.
This is a concrete remote-payload execution chain activated by importing the package, unrelated to the stated React-component purpose. No lifecycle hook is needed for the package to execu...
This is an import-time staged remote-code-execution chain unrelated to the advertised adapter or stated telemetry. No signature, hash, or user action protects the downloaded executable.