Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:05 UTC. Ordered by latest scan.
This is concrete import-time arbitrary-code execution from externally staged content, not a package-aligned SDK function. The absence of the loader in source makes the shipped distributio...
The package's benign exported helpers do not justify a postinstall flow that retrieves and executes mutable remote code. This is concrete install-time remote code execution.
Direct source inspection confirms an obfuscated install-time reverse-shell payload with no legitimate implementation to justify it. The package is malicious and should be blocked.
Direct source inspection confirms import-time reverse-shell behavior and outbound host callback. This is concrete unauthorized remote command execution, not merely a scanner match.