Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:04 UTC. Ordered by latest scan.
Direct source inspection confirms concrete reverse-shell behavior reachable through the package export and bundled CI check script. This is not package-aligned functionality and enables u...
Direct source inspection confirms concrete reverse-shell behavior in the package main entrypoint, with check.js showing a caller path. Lack of lifecycle execution reduces automatic trigge...
Direct source inspection confirms a reachable exported function executes a remote script through bash. This is malicious remote code execution rather than a noisy scanner-only finding.
Direct source inspection confirms import-time obfuscated remote executable download and execution with a deceptive Chrome path, unrelated to multer middleware. This is concrete malware be...