Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:23 UTC. Ordered by latest scan.
This is a concrete import-time remote code execution chain concealed in unrelated glob-matching code. The absence of an install hook does not mitigate execution when an application import...
This is concrete import-time remote code execution with a detached child process and self-removal behavior. The absence of an npm lifecycle hook does not mitigate execution through the co...
This is concrete remote code execution activated by a normal import, not merely a validator. The signing gate authenticates the publisher-controlled remote payload but does not make its a...
This is a concealed remote code loader, not ordinary image parsing. The absence of an install hook does not mitigate runtime execution of a payload selected by attacker-controlled image d...