Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 20:24 UTC. Ordered by latest scan.
Direct source inspection confirms an obfuscated install-time reverse-shell payload with no legitimate implementation to justify it. The package is malicious and should be blocked.
Direct source inspection confirms import-time reverse-shell behavior and outbound host callback. This is concrete unauthorized remote command execution, not merely a scanner match.
Direct source inspection confirms import-time reverse-shell behavior in the package main entrypoint. The lack of lifecycle scripts does not mitigate execution when the entrypoint is impor...
Source inspection confirms an import-time reverse shell to a hard-coded external endpoint. The benign node file and absence of lifecycle scripts do not mitigate the malicious package entr...