Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
The package contains a runtime chain that automatically executes remotely supplied binaries, persists background services, and authorizes container-to-host SSH access. These capabilities...
The package contains a complete server-driven remote shell execution path and an automatic forced self-update path with optional sudo. Its harmless install banners do not mitigate these r...
The package creates concrete remote code execution and credential exposure paths when its user-facing commands run. Obfuscation and silent global self-updating further remove meaningful u...
This is an automatically reachable remote-code-execution chain from the package's browser entrypoint. The lack of an install hook does not mitigate runtime execution of unpinned remote Ja...