Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 07:49 UTC. Ordered by latest scan.
This is concrete, import-time staged remote-code execution with no legitimate functionality exposed by the package that requires it. The absence of lifecycle hooks does not mitigate runti...
This is concrete import-time remote payload execution, not package-aligned telemetry. The absence of npm lifecycle hooks does not mitigate the reachable malicious entrypoint.
This is concrete import-time remote payload execution, unrelated to the package's stated wrapper purpose. No lifecycle hook is needed because requiring the public module activates the chain.
This is concrete automatic remote payload execution unrelated to the documented abstraction API. No install hook is needed because ordinary package import activates the chain.