Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:56 UTC. Ordered by latest scan.
The package’s declared ESLint configuration is small, but its mandatory preinstall executes an unrelated obfuscated payload with dynamic eval and credential-focused behavior. This is conc...
The install hook creates a concrete, concealed remote-code execution path. This behavior is incompatible with a Jest config package.
The install hook executes a concealed, unrelated payload with remote dynamic evaluation and credential-handling primitives. This is concrete malicious install-time behavior, not package-a...
The package's advertised example source does not justify an obfuscated install-time runtime downloader or the bundled credential-aware, remotely evaluated payload. This is concrete malici...