Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 02:24 UTC. Ordered by latest scan.
This is a concrete, automatically reachable remote-code-execution chain unrelated to the stated promocode SDK. The unused telemetry module contains a parallel payload-loader implementatio...
This is an import-time, covert remote-code-execution chain unrelated to the declared log formatter functionality. Lack of an npm lifecycle hook does not mitigate execution on normal packa...
The package's advertised logging behavior does not justify an import-time downloader and detached binary launcher. No lifecycle script is needed because the attack is activated by normal...
The downloader/executor is reachable at import time and its payload is fully remote-controlled, with obfuscated endpoints and concealed failure handling. This is concrete malware behavior...