Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:14 UTC. Ordered by latest scan.
The package performs unconsented install-time remote shell execution and privileged host mutation. This is a concrete malicious install chain, not merely a user-invoked setup capability.
The package contains an unconsented import-time self-updater that invokes npm with consumer-project privileges and changes consumer files. This is a concrete remote update and execution c...
The package contains a concrete arbitrary-command execution path fed by a remote AI response, plus intrusive lifecycle behavior. This exceeds normal Git-client functionality and creates a...
The package contains an automatic install-time remote payload loader that executes unaudited code from a hard-coded endpoint. This is concrete malware behavior, regardless of the benign-l...