Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:43 UTC. Ordered by latest scan.
This is a concrete import-time remote payload execution chain, not ordinary telemetry. The unused-looking telemetry source contains the same downloader/launcher design, reinforcing intent.
Source establishes an import-reachable, network-delivered arbitrary native payload execution chain. No lifecycle hook is needed for this concrete runtime compromise.
This package’s documented timeline API is inert, while its import-time side effect is a concealed cross-platform downloader and executor. The lack of lifecycle hooks does not mitigate run...
The hidden import-time loader establishes a concrete remote payload execution chain. Absence of npm lifecycle hooks does not mitigate execution on normal module use.