Investigate remote code execution and remote payload execution, including code fetched or launched by a package. These reports have OSV or public advisory evidence. Each report identifies the package version, supporting evidence, advisory sources, and current Firewall decision.
Updated 8 Oct 2026, 08:48 UTC. Ordered by latest scan.
The main entrypoint exposes an explicit command that downloads and executes remote code, establishing a concrete remote code execution capability. The package has no install lifecycle hoo...
Inspected source contains concrete exfiltration and remote code execution unrelated to CSS polyfill functionality. The registry manifest provides a loading path to this active payload.
Inspected source proves automatic host-data transmission and execution of remote server commands during installation. This is concrete malicious install behavior warranting a publication...
The active entrypoint connects ordinary middleware initialization to concealed remote code execution. The encoded endpoint, detached execution, and unrestricted response evaluation suppor...