Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
The reachable encrypted decrypt-and-require chain is a concrete hidden code-execution mechanism. Absence of an install hook does not remove the runtime execution risk.
This is a concrete, reachable arbitrary binary execution chain, not merely ordinary tunnel networking. The absence of an npm install hook does not mitigate the runtime remote-code-executi...
The unverified remote-script execution is a concrete remote-code-execution path, and the daemon also sends identified logs to a default external endpoint. Absence of an npm lifecycle hook...
Postinstall downloads and installs an unsigned native binary from a hardcoded IP with TLS verification disabled, then the CLI executes it. That is a concrete remote payload chain, not a f...