Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 12:33 UTC. Ordered by latest scan.
The source contains a concrete, reachable remote download-and-execute chain. Absence of an install hook limits automatic activation but does not remove the malicious runtime payload.
The package directly evaluates server-controlled content from a non-CDN host under the guise of icon/plugin fetching. Absence of install-time execution limits the trigger but does not rem...
This is a concealed staged remote-code-execution chain in a package presented as an SVG utility. It is reachable through documented runtime APIs, despite no install hook in this package's...
Source inspection confirms a reachable remote-download-to-shell execution chain with no legitimate package functionality evident. Absence of lifecycle hooks limits automatic activation bu...