Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 21:54 UTC. Ordered by latest scan.
Direct source inspection confirms an unconsented install-time remote executable download and hidden execution chain. This is concrete malware behavior, not a package-aligned setup action.
This is a concrete import-time remote-code-execution chain, not a normal request helper. The hard-coded network payload is executed without user action or integrity verification.
This is a concrete browser-side remote payload chain rather than a benign utility: it automatically obscures the host UI and hands control to an external page. No lifecycle hook is needed...
The package contains an explicit detached remote-code loader activated by normal middleware use. Absence of an install hook does not mitigate runtime arbitrary code execution.