Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 19:38 UTC. Ordered by latest scan.
Source inspection confirms a concrete remote-code-execution path, albeit user-invoked rather than lifecycle-triggered. The hard-coded endpoint and deceptive package functionality support...
The package contains a concrete, remotely controlled arbitrary-code execution path unrelated to its stated Tailwind/forms purpose. Lack of an install hook limits automatic activation but...
The package contains a concrete remote code execution loader with a hard-coded, non-package-aligned IP endpoint. Lack of an install hook limits automatic execution but does not remove the...
This is a concrete remote-code-execution loader, not a legitimate icon fetch path. Lack of lifecycle hooks limits automatic activation but does not remove the malicious exported capability.