Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 15:26 UTC. Ordered by latest scan.
The package contains a concrete, reachable import-time remote payload execution chain unrelated to its advertised minimal interface. This is malicious behavior, not benign telemetry.
This is concrete, automatically triggered remote native payload execution unrelated to the declared visual-components package. The telemetry-themed library duplicates the same downloader/...
The public entrypoint unconditionally triggers an obfuscated downloader-executor at runtime. No legitimate SDK functionality explains remote binary retrieval and detached execution.
This is a concrete import-time staged-payload execution chain unrelated to the documented core-runtime API. Absence of an install hook does not mitigate execution when consumers import th...