Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 01:46 UTC. Ordered by latest scan.
This is concrete, concealed import-time remote code execution unrelated to the advertised date-range library. The similarly capable telemetry file reinforces the intent but is not require...
The source establishes an import-time download-and-execute chain with no payload authentication. The unused telemetry module reinforces the same behavior but is not needed for the verdict.
Source directly establishes import-time remote binary retrieval and detached execution; no benign package function requires this behavior. The absence of lifecycle hooks does not mitigate...
The package has no install hook, but its normal import path performs an unconsented remote-binary download and execution chain. The telemetry naming and opt-out variables do not make this...