Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:02 UTC. Ordered by latest scan.
This package contains a concrete, user-triggered remote code execution chain hidden inside its certificate generator. The behavior is unrelated to its stated purpose and warrants blocking.
This package performs an obfuscated, unconsented install-time remote payload download and execution. The behavior is concrete malware, not a package-aligned setup step.
This is a concrete install-time persistence and C2 malware chain, not a package-aligned administrative tool. The source implements remote shell execution, surveillance, exfiltration, and...
This is concrete import-time execution of decrypted staged code from another package path, not a normal blockchain-library function. The absence of lifecycle hooks does not mitigate the e...