Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 09:38 UTC. Ordered by latest scan.
This is concrete unconsented remote native payload execution on normal package import, not legitimate telemetry. The lack of lifecycle hooks does not mitigate the reachable import-time ex...
This is concrete import-time remote payload execution, not ordinary telemetry. The loader is concealed behind a benign entrypoint and uses multiple remote fallback channels.
This is a concrete import-time remote payload delivery and execution chain unrelated to the package's stated markdown adapter API. The lack of lifecycle hooks does not mitigate execution...
Source establishes an import-time, unauthenticated remote-code-execution chain; it is not legitimate telemetry. The lack of an install hook does not mitigate execution during normal packa...