Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 01:53 UTC. Ordered by latest scan.
Direct source inspection confirms a deterministic install-time reverse shell in package.json. This is concrete malicious behavior independent of the otherwise package-aligned Paperclip ma...
Direct source inspection confirms an automatic lifecycle hook implementing a hardcoded reverse shell. This is concrete malicious install-time remote code execution, not package-aligned be...
Direct source inspection confirms a runtime fetch-and-eval path for remote JavaScript, which is a concrete remote-code execution/staged payload behavior. The absence of install hooks redu...
Static source inspection confirms unconsented import-time execution of a detached helper that retrieves and evaluates remote payloads. This is concrete malicious behavior, not merely a su...