Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:50 UTC. Ordered by latest scan.
Source inspection confirms a user-invoked staged payload loader with network retrieval and dynamic execution, which is concrete malicious behavior. The absence of install hooks lowers tri...
Static source inspection confirms a concealed, package-misaligned remote code execution path in index.js. Absence of lifecycle execution lowers trigger breadth but does not make the expos...
Direct source inspection confirms a hidden, package-misaligned remote payload execution path in index.js. Although not install-time, the exported runtime method is concrete malicious beha...
Static source inspection confirms concrete import-time remote code execution in index.js, not merely a scanner hint. This is unconsented executable payload loading unrelated to the stated...