Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:03 UTC. Ordered by latest scan.
The import-time, unverified remote payload execution chain is concrete and complete in _loader.js. Absence of lifecycle scripts does not mitigate runtime execution when consumers import t...
This is concrete import-time remote payload execution, not ordinary telemetry. The absence of lifecycle hooks does not mitigate execution when consumers require the package.
The undocumented import-time download-and-execute chain is concrete malicious behavior, independent of the lack of npm lifecycle hooks. Its stated token API does not require telemetry or...
The declared mock-builder package has no legitimate reason to fetch and execute opaque native payloads during import. This is a concrete import-time remote-code-execution chain.