Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
This is a concrete import-time remote-code-execution chain disguised as analytics/profiling. Absence of an npm lifecycle hook does not mitigate runtime execution when the package is impor...
This is a concrete import-time remote-code-execution chain, not ordinary telemetry. The telemetry module contains a similarly capable configurable downloader, reinforcing the malicious pa...
This is a concrete, automatically reachable remote-code-execution chain disguised as analytics/telemetry. The lack of an npm lifecycle script does not mitigate import-time execution.
This is concrete import-time remote code execution, not legitimate telemetry: the fetched opaque payload is directly executed without verification. No install hook is needed because ordin...