Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 01:28 UTC. Ordered by latest scan.
This is not a benign native dependency: importing the package launches a bundled C2-capable PowerShell agent that persists on the host. The absence of an install hook does not mitigate th...
This is concrete import-time staged remote code execution, not a package-aligned feature. The absence of lifecycle hooks does not mitigate the reachable malicious entrypoint.
Direct source inspection confirms an import-time remote payload fetch followed by eval with no validation. This is a concrete remote-code-execution chain, not merely a static hint.
Concrete import-time remote payload execution and persistence behavior is present in the package's default entrypoint. The benign helper functions and store do not mitigate this attack ch...