Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:11 UTC. Ordered by latest scan.
This is not a benign library artifact: the package auto-executes third-party remote code and installs a browser request-routing proxy to unrelated infrastructure. No install hook is neede...
Direct source inspection confirms automatic remote-code execution and local obfuscated dynamic execution when the declared HTML entrypoint is opened. Absence of npm lifecycle hooks does n...
Source inspection confirms executable remote code loading and a persistent browser request-interception proxy tied to unrelated hosts. This is concrete harmful behavior despite the absenc...
Direct source and published-entrypoint inspection confirms an import-triggered, encrypted staged payload executed by a detached Node subprocess. No lifecycle hook is needed for this concr...