Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:25 UTC. Ordered by latest scan.
Source inspection confirms import-time remote binary staging and execution. No user action, explicit configuration, or lifecycle hook is required beyond loading the package.
This is a concrete, import-triggered remote native payload execution chain unrelated to the advertised widget. The duplicate telemetry implementation corroborates the same downloader/laun...
The advertised interceptor has no functional connection to hidden import-time remote executable delivery. This is a concrete remote-code-execution chain, not merely telemetry behavior.
This is a concrete staged payload chain reachable on ordinary import, not a configured telemetry feature. No lifecycle hook is needed because the malicious action runs from the main entry...