Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:10 UTC. Ordered by latest scan.
The package's public entrypoint automatically executes a concealed downloader and detached payload launcher. The behavior is concrete, reachable on import, and unrelated to the stated pic...
This is concrete import-time remote payload staging and execution, disguised as telemetry compatibility code. No lifecycle hook is needed for the attack to reach consumers.
This is an import-time remote payload execution chain unrelated to the declared banner abstraction. No install hook is needed because ordinary package use triggers it.
This is a concrete, automatically reachable remote-code-execution chain, not normal telemetry. The absence of an install hook does not mitigate execution on ordinary package import.