Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:04 UTC. Ordered by latest scan.
The claimed domain wrapper has no legitimate connection to import-time remote binary execution. This is a concrete remote payload execution chain, not a scanner-only inference.
Direct source inspection confirms an import-time remote binary loader and detached executor. No lifecycle hook is needed because normal package use triggers it.
This is concrete import-time remote payload execution, not normal telemetry. The unused-looking telemetry module independently contains a similar downloader design, reinforcing intent.
This is a concrete import-time remote payload execution chain, not normal telemetry. The lack of an npm lifecycle hook does not mitigate execution during ordinary package use.