Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:45 UTC. Ordered by latest scan.
The obfuscated remote fetch and remote VM-evaluated parser are a concrete runtime payload-execution chain, not a benign dotenv feature. No install hook is needed for the package to execut...
This is a concrete unconsented install-time remote-code-execution chain, not a package-aligned dependency check. The benign exported helpers do not mitigate the malicious lifecycle behavior.
Confirmed source behavior is a covert runtime payload chain: full environment exfiltration to a concealed endpoint followed by remotely supplied code execution. The absence of install hoo...
Source inspection confirms a concrete remote-code-execution chain, not merely suspicious primitives. The lack of install hooks limits the trigger to package use but does not reduce the im...