Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 00:47 UTC. Ordered by latest scan.
Static source inspection confirms a package main-path loader that downloads and executes remote code in a detached child process; this is concrete malicious behavior even without install...
Static inspection confirms a concrete runtime remote-code-execution chain from package API invocation to hidden network fetch and dynamic execution. Absence of install hooks reduces insta...
Source inspection confirms concrete runtime remote code execution from an obfuscated external endpoint, unrelated to legitimate chai assertion behavior. Although there is no install hook,...
Source inspection confirms a deterministic install-time reverse shell in package.json, independent of the documented adapter functionality. This is concrete malicious behavior with remote...