Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 02:13 UTC. Ordered by latest scan.
The preinstall hook contains a concrete, obfuscated remote fetch-and-eval chain. This is unconsented install-time remote code execution, not functionality required by a React UI package.
Direct source inspection confirms an install-time staged remote payload execution chain. The normal library entrypoints do not mitigate the malicious lifecycle behavior.
The concealed install-time fetch-and-eval chain is a concrete remote-code-execution mechanism, independent of the benign-looking library entrypoints. This warrants blocking publication.
Source inspection confirms an obfuscated, install-time remote payload execution chain. The normal library entrypoints do not mitigate the preinstall compromise.