Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:21 UTC. Ordered by latest scan.
The stated calendar/streak functionality does not require fetching and executing an opaque native binary. The behavior is concealed with character-code URL construction and runs automatic...
The Windows native binary contains and invokes a concrete remote PowerShell execution chain during addon initialization. The benign package description and Linux SHA-256 implementation do...
The package contains a concrete concealed remote-code execution chain unrelated to its advertised scaffolding function. Absence of an install hook does not mitigate execution when its ser...
This is a concrete, concealed remote-code-execution loader, not an SVG utility feature. Lack of install hooks limits automatic activation but does not remove the malicious capability.