Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 18:51 UTC. Ordered by latest scan.
Source inspection confirms a concealed remote-code-execution path in src/index.cjs. It is not install-time, but it is concrete malicious functionality rather than a package-aligned feature.
This is more than a benign scanner primitive: source confirms remotely supplied executable hook replacement in a broad AI-agent control surface, plus interception and concealment of agent...
The package is a staged remote-code-execution loader, not a normal icon fetcher. The absence of lifecycle hooks limits automatic activation but does not remove the concrete runtime attack...
This is a concrete remote-code-execution loader unrelated to the documented mutex functionality. Lack of lifecycle hooks does not mitigate execution when the exported API is called.