Loading npm security reports…
Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 10 Oct 2026, 02:13 UTC. Ordered by latest scan.
Direct source inspection confirms a hidden, package-misaligned remote payload execution path in index.js. Although not install-time, the exported runtime method is concrete malicious beha...
Static source inspection confirms concrete import-time remote code execution in index.js, not merely a scanner hint. This is unconsented executable payload loading unrelated to the stated...