Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports include LPM Firewall detections. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
This is a concrete install-time remote-code-execution chain, not a package feature. The mismatched README further supports deceptive intent.
This is a concrete credential-exfiltration and remote-code-execution chain activated by ordinary package use. Lack of an install hook does not mitigate the import-time attack.
The automatic installation and persistence of a differently named package is concrete unconsented remote-code delivery behavior, not a package-aligned API operation. Absence of lifecycle...
Direct inspection confirms concrete install-time remote shell access, not merely a suspicious primitive. This is malicious behavior with no user action required beyond installing the pack...