Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:09 UTC. Ordered by latest scan.
The package contains concrete import-time arbitrary code execution through decrypted external payloads and detached child processes. The discrepancy between source entry/build configurati...
The package provides no library behavior; its import-time browser payload covertly embeds an externally controlled destination. The domain-rotation publishing helper reinforces intentiona...
The obfuscated remote fetch and remote VM-evaluated parser are a concrete runtime payload-execution chain, not a benign dotenv feature. No install hook is needed for the package to execut...
This is a concrete unconsented install-time remote-code-execution chain, not a package-aligned dependency check. The benign exported helpers do not mitigate the malicious lifecycle behavior.