Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 04:28 UTC. Ordered by latest scan.
The package contains an explicit detached remote-code loader activated by normal middleware use. Absence of an install hook does not mitigate runtime arbitrary code execution.
Source inspection confirms a concrete, obfuscated runtime dependency-install and execution chain triggered by normal documented APIs. Lack of an npm lifecycle hook limits the trigger but...
Source inspection confirms a concrete remote payload fetch-and-execute chain, independent of scanner labels. The lack of install hooks does not mitigate runtime arbitrary code execution i...
This is a concrete remote code execution backdoor, not required for SVG retrieval. Absence of install hooks limits automatic activation but does not remove the malicious exported capability.