Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 13:32 UTC. Ordered by latest scan.
The malicious execution chain is reachable at normal import time, not merely dormant in an unused helper. Remote content has no integrity validation before execution.
The reachable import-time bootstrap implements a concrete remote payload delivery and execution chain. The lack of an npm lifecycle hook does not mitigate arbitrary code execution on norm...
Confirmed import-time staged remote code execution in all published entrypoints. The absence of install hooks does not mitigate the concrete runtime execution chain.
Direct inspection confirms concrete obfuscated remote payload retrieval, eval, and detached process execution in the main entrypoint. This is malicious regardless of the absence of instal...