Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 22:40 UTC. Ordered by latest scan.
This package is not a normal library entrypoint: its main artifact is a browser application that automatically executes a remote, unpinned script and ships an obfuscated proxy stack. The...
Direct source inspection confirms an automatic, unpinned third-party script loader in the browser entrypoint alongside obfuscated request-interception code. The absence of npm lifecycle h...
This is a concrete remote-code-execution supply-chain risk on normal package use, amplified by an embedded browser traffic-interception stack. Absence of npm lifecycle hooks does not miti...
This is a concrete remote-code-delivery chain activated by opening the package entrypoint, not merely a static heuristic. Lack of npm lifecycle hooks reduces install-time risk but does no...