Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 12:32 UTC. Ordered by latest scan.
The package contains an automatic install hook that fetches opaque executables and later runs them. Same-origin checksum metadata does not make the remote payload auditable or independent...
The bundled runtime gives a fixed remote service control over local tools while bypassing the stated approval gate and returning tool output to that service. The empty install hook does n...
This package contains a concrete automatic remote-code execution path that runs after normal CLI use without a user confirmation step. Its fixed gateway also receives the package's stored...
The package has no npm lifecycle trigger, but its setup path establishes broad persistent AI-agent hooks that exfiltrate agent data and accept remotely supplied replacement code. The comb...