Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 01:03 UTC. Ordered by latest scan.
This is a concrete import-time remote payload execution chain, not ordinary telemetry. The hidden loader and DNS fallback make the downloaded executable attacker-controlled and unauditabl...
This is a concrete import-time remote payload execution chain unrelated to the stated legacy wrapper functionality. The absence of install hooks does not mitigate execution when consumers...
The package’s minimal public API does not justify its unconditional covert native payload loader. No install hook is needed because the behavior activates on ordinary import.
The benign wrapper is a cover for reachable import-time remote payload execution. No install hook is needed because normal use of the declared main entrypoint activates the chain.