Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 10:22 UTC. Ordered by latest scan.
This is a concrete import-time remote-code-execution backdoor with detached-process persistence. The absence of an install hook does not reduce the risk to consumers that import the decla...
This is an automatic remote payload execution chain with no checksum or signature verification, compounded by quarantine removal. Although the host is package-aligned and no direct secret...
This package contains an import-triggered detached remote-code loader, not the runtime utilities claimed by its manifest. The remote payload is executed with Node module access, creating...
This is a concrete install-time remote-code-execution backdoor, not functionality required by the stated n8n health-monitor node. The listener is exposed on all interfaces and has no auth...