Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 9 Oct 2026, 23:24 UTC. Ordered by latest scan.
No install-time hook exists, but the shipped entrypoint directly executes unpinned remote code and installs a browser request-interception proxy that forwards request data to an unrelated...
No install-time host mutation occurs, but automatic unpinned third-party code execution is a concrete malicious supply-chain attack surface. Obfuscation and the bundled traffic-intercepti...
Source inspection confirms browser-side remote payload execution and a persistent service-worker proxy path, not merely scanner-observed obfuscation. Although installation itself has no l...
This is a republished npm package whose HTML entry embeds remote executable code and activates a service-worker traffic proxy to unrelated external infrastructure. The runtime behavior is...