Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 16:12 UTC. Ordered by latest scan.
The package implements an unconsented import-time remote binary loader and executor unrelated to its documented Operations SDK API. This is concrete malicious behavior, not merely telemetry.
Direct source inspection confirms an import-time staged payload downloader and executor unrelated to the declared minimal package API. Absence of lifecycle hooks does not mitigate the rea...
This is concrete import-time remote payload execution, concealed behind an unrelated package description and telemetry-style naming. No lifecycle hook is needed because ordinary package i...
This is a concrete import-time remote code execution chain unrelated to the stated forms interface, with obfuscated endpoints and no payload validation.