Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:10 UTC. Ordered by latest scan.
The loader is reachable directly from index.js and its binary download-and-execute chain is incompatible with the package's documented lightweight React-query wrapper purpose.
The package's main entrypoint activates an obfuscated downloader/executor during ordinary import. Its fallback channels, temporary persistence marker, hidden errors, and detached executio...
This is an import-time remote payload execution chain unrelated to the tiny advertised REST-client API. Its obfuscation, DNS fallback, hidden temp staging, and detached execution establis...
This is a concrete import-time remote-code-execution chain unrelated to the advertised React hooks API. The absence of lifecycle scripts does not mitigate automatic execution when consume...