Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:52 UTC. Ordered by latest scan.
No install hook affects the host, but runtime source confirms remote executable loading and an obfuscated service-worker proxy that relays request data. This is a concrete unsafe payload...
This is not merely a static hint: direct source inspection confirms an unconditional remote script execution path from the declared entrypoint. The lack of npm lifecycle hooks limits inst...
Direct execution of an unpinned, unrelated remote script is a concrete remote-payload chain, not merely a static heuristic. The absence of npm lifecycle hooks does not mitigate runtime br...
This package does not execute during npm installation, but its declared runtime entrypoint grants an unrelated remote host arbitrary code execution. That is a concrete, unconsented remote...