Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 09:16 UTC. Ordered by latest scan.
The package’s normal import path implements an unconsented staged payload downloader and executor. This is malicious regardless of the absence of npm lifecycle scripts.
Direct source inspection confirms an import-triggered download-and-execute chain. The lack of install hooks does not mitigate arbitrary code execution when consumers import the package.
Direct source inspection confirms an import-time downloader/dropper/executor with concealed endpoints and no payload validation. The absence of an npm lifecycle hook does not mitigate exe...
The source establishes concrete import-time remote code execution, not merely telemetry behavior. No lifecycle hook is needed because the main entrypoint triggers it for package consumers.