Investigate remote code execution and remote payload execution, including code fetched or launched by a package. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 13:53 UTC. Ordered by latest scan.
This is a concrete credential-exfiltration and remote-code-execution chain activated by ordinary package use. Lack of an install hook does not mitigate the import-time attack.
The automatic installation and persistence of a differently named package is concrete unconsented remote-code delivery behavior, not a package-aligned API operation. Absence of lifecycle...
Direct inspection confirms concrete install-time remote shell access, not merely a suspicious primitive. This is malicious behavior with no user action required beyond installing the pack...
The concealed SVG-comment payload loader and immediate dynamic execution are unrelated to normal PostCSS processing and provide a concrete arbitrary-code-execution path.