Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 06:26 UTC. Ordered by latest scan.
Direct inspection confirms an obfuscated remote fetch plus eval in index.js:41 on the package's main runtime path. This is concrete malicious behavior, not a package-aligned cookie parsin...
Read-only source inspection confirms a runtime remote fetch plus eval chain in the package's main code path, using an obscured endpoint unrelated to cookie parsing. Absence of install hoo...
Source inspection confirms a concrete runtime malicious chain: an obscured remote endpoint controls code passed to eval inside the package's primary exported function. Absence of install...
Source inspection confirms a hidden network fetch and eval in index.js, unrelated to cookie parsing and activated during normal runtime use. This is concrete malicious remote code executi...