Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
The package combines reviewer manipulation with automatic execution of unpinned remote code and credential handling. The lack of an npm install hook reduces scope but does not neutralize...
The package contains a concrete remote download-and-shell execution path plus silent privileged self-updating. Its install hooks are cosmetic, but runtime behavior is sufficient to block...
The package performs unconsented install-time remote shell execution and privileged host mutation. This is a concrete malicious install chain, not merely a user-invoked setup capability.
The package contains an unconsented import-time self-updater that invokes npm with consumer-project privileges and changes consumer files. This is a concrete remote update and execution c...
The package contains a concrete arbitrary-command execution path fed by a remote AI response, plus intrusive lifecycle behavior. This exceeds normal Git-client functionality and creates a...