Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 14:35 UTC. Ordered by latest scan.
This is concrete import-time remote code execution, not package-aligned telemetry. The unused telemetry file contains a similar downloader pattern but does not mitigate the active _shim.j...
This is a concrete, silent import-time remote payload execution chain unrelated to the declared select-user library. Absence of npm lifecycle hooks does not mitigate the reachable runtime...
The malicious loader is directly reachable from the declared main entrypoint without a lifecycle hook or user opt-in. Its download-and-execute chain is concrete and unrelated to the adver...
This is concrete runtime remote-code execution, not ordinary telemetry: a minimal adapter imports a hidden loader that retrieves and launches unsigned binaries. The absence of lifecycle h...