Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
The package contains an import-time remote binary downloader and launcher disguised as telemetry. The lack of install hooks does not mitigate runtime arbitrary code execution on import.
The package has no install hook, but its normal import path automatically downloads and executes remote, unverified binaries. The claimed telemetry/profiler functionality does not justify...
This is concrete, automatic remote payload execution on ordinary package import, not legitimate telemetry behavior.
The concrete import-time remote-payload download and detached execution chain establishes malicious behavior. Lack of an npm lifecycle hook does not reduce the runtime RCE impact.