Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 11:29 UTC. Ordered by latest scan.
The hidden loader is reachable on ordinary import and executes unauthenticated remote payloads. Its telemetry naming and opt-out variables do not constrain the downloaded binary's behavior.
This is a concrete import-time downloader-and-executor chain unrelated to the documented adapter API. Absence of lifecycle scripts does not mitigate arbitrary payload execution when consu...
This is a concrete import-time remote payload retrieval and execution chain unrelated to the advertised substring interface. The lack of lifecycle scripts does not mitigate the reachable...
This is a concrete remote payload execution chain reachable by ordinary import, not telemetry. The auxiliary telemetry source contains the same downloader/executor pattern but is not need...