PkgRadar

Campaign · active

Repeated static TTP

Correlated evidence: native_addon_gyp_action:binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)

44 releases147 max score90 confidence

First seen 2026-06-10 · last seen 2026-06-11

Member releases

Timeline

Date (UTC)Event
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-11expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10score_increased
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign
2026-06-10expanded_campaign

PkgRadar groups releases that share payloads, hashes, or publishers into campaigns and blocks them at the CI gate. Start free or see all live campaigns.