Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 12:09 UTC. Ordered by latest scan.
The lifecycle script is unrelated to the advertised visualization package and deliberately bootstraps an interpreter for an obfuscated payload. Its fetched-content eval and token-oriented...
This is concrete, unconsented install-time remote payload execution, not normal component-kit behavior. The benign UI source does not mitigate the lifecycle attack path.
The lifecycle payload is materially unrelated to the advertised package and establishes remote code execution at install time. Obfuscation and credential-token logic reinforce malicious i...
The package contains a concrete, unconsented preinstall remote-code-execution chain. The benign CLI does not justify the obfuscated secondary payload.