Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 11:49 UTC. Ordered by latest scan.
Source directly implements a remote download-and-execute chain through Bash. Although it is not install-time, it is an exported package capability with a concrete malicious payload endpoint.
This is an unconsented postinstall remote-code loader disguised as an install check. The packaged library itself is benign math, but its lifecycle hook creates a concrete execution chain.
This is a concrete remote-code-execution chain, activated during normal dotenv configuration and concealed by an obfuscated endpoint. It is not install-time, but it is malicious runtime b...
The source contains an unconditional import-time remote-code loader. This is concrete malicious behavior, irrespective of the lack of lifecycle hooks.