Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 16:33 UTC. Ordered by latest scan.
This is a concrete import-time staged payload chain with arbitrary binary execution, unrelated to the advertised pub/sub adapter. The absence of npm lifecycle hooks does not mitigate the...
This is a concrete import-time remote-code-execution chain, not ordinary telemetry. The absence of npm lifecycle hooks does not mitigate activation through the package main entrypoint.
The package contains an import-time, obfuscated remote payload loader that executes unverified downloaded binaries. Lack of lifecycle hooks does not mitigate the reachable runtime attack...
This is concrete import-time remote payload execution, unrelated to the advertised metrics collector. The absence of an install hook does not mitigate execution when consumers import the...