Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 05:49 UTC. Ordered by latest scan.
The import-time bootstrap is a concrete, stealthy remote-code-execution chain. Absence of lifecycle hooks does not mitigate execution on ordinary package import.
This is a concrete import-time remote payload execution chain unrelated to the stated React-components purpose. The absence of lifecycle hooks does not mitigate execution on normal packag...
This is a concrete import-time remote payload execution chain unrelated to the advertised React component package. The absence of lifecycle hooks does not mitigate runtime execution on no...
Concrete import-time download-and-execute behavior is present in the published entrypoint. The lack of an install hook does not mitigate runtime compromise on normal package use.