Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 00:09 UTC. Ordered by latest scan.
The package contains a concrete remote payload loader and evaluator reached through its public API. Absence of an install hook does not mitigate this runtime RCE behavior.
The package contains an unconditional import-time remote payload loader with dynamic code execution. Absence of npm lifecycle hooks does not mitigate runtime compromise of every consumer...
Source inspection confirms a concrete remote-code-execution chain behind an exported API, not merely static similarity. Although it has no install hook, the stealthy detached remote paylo...
The source confirms a runtime path from normal package use to a detached helper that fetches and executes remote code; this is concrete malicious behavior even without install hooks. Scan...