Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 03:44 UTC. Ordered by latest scan.
Source directly establishes import-time download-and-execute behavior with no user command or consent boundary. The telemetry module independently contains the same payload-loader pattern...
This is a concrete, stealthy remote-payload execution chain activated by a normal package import. The telemetry naming and opt-out variables do not constrain the downloaded code or make t...
This is concrete automatic remote payload execution on package import, unrelated to the documented test-harness functionality. It is malicious regardless of the absence of npm lifecycle h...
This is concrete, silent import-time remote payload staging and execution, not ordinary telemetry. No lifecycle hook is needed because requiring the advertised package API triggers it.