Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 10:48 UTC. Ordered by latest scan.
This is concrete, automatic remote payload execution unrelated to the declared UI-toolkit functionality. The absence of lifecycle hooks does not mitigate the import-time execution path.
This is a confirmed import-time downloader-and-executor, not ordinary telemetry. No lifecycle hook is needed because the package entrypoint activates it.
This is a concrete, import-triggered remote-code-execution chain unrelated to the documented minimal SDK API. The absence of an install hook does not mitigate execution on normal package...
This is concrete, automatic remote-code execution unrelated to the advertised API adapter. The lack of lifecycle hooks does not mitigate import-time execution.