PkgRadar

npm · registry.npmjs.org

@askalf/dario

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 4.8.71

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/runtime-fingerprint.js
mediumRemote Payloadmatched "curl " · package/dist/runtime-fingerprint.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.8.71Review392026-06-13
4.8.70Review392026-06-13
4.8.69Review392026-06-13
4.8.68Review392026-06-12
4.8.67Review572026-06-12
4.8.66Review572026-06-12
4.8.65Review392026-06-12
4.8.64Review392026-06-12
4.8.63Review392026-06-12
4.8.62Review392026-06-11
4.8.61Review392026-06-11
4.8.60Review392026-06-11
4.8.59Review392026-06-10
4.8.58Review572026-06-10
4.8.57Review392026-06-10
4.8.56Review572026-06-10
4.8.54Review392026-06-10
4.8.55Review392026-06-10
4.8.53Review572026-06-09
4.8.52Review392026-06-09
4.8.51Review572026-06-09
4.8.50Review392026-06-09
4.8.49Review392026-06-09
4.8.48Review392026-06-09
4.8.47Review392026-06-09
4.8.46Review392026-06-09
4.8.45Review392026-06-09
4.8.44Review392026-06-09
4.8.43Review572026-06-08
4.8.42Review392026-06-08
4.8.41Review392026-06-07
4.8.40Review392026-06-07
4.8.39Review392026-06-07
4.8.38Review392026-06-07
4.8.37Review572026-06-07
4.8.36Review392026-06-07
4.8.35Review392026-06-06
4.8.34Review392026-06-06
4.8.33Review392026-06-05
4.8.32Review392026-06-04
4.8.30Review392026-06-04
4.8.31Review392026-06-04
4.8.27Review392026-06-03
4.8.26Review572026-06-02
4.8.25Review392026-06-02
4.8.24Review392026-06-02
4.8.23Review392026-06-02
4.8.22Review392026-05-31
4.8.21Review572026-05-31
4.8.20Review392026-05-31
4.8.19Review392026-05-30
4.8.18Review392026-05-29
4.8.17Review392026-05-29
4.8.16Review392026-05-29
4.8.15Review392026-05-29
4.8.14Review572026-05-29
4.8.12Review392026-05-28
4.8.13Review392026-05-28
4.8.11Review572026-05-28
4.8.9Review82026-05-27
4.8.10Review82026-05-27

Block this in CI

PkgRadar gates @askalf/dario (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @askalf/[email protected]