npm · registry.npmjs.org
@ayunlove/bails
Remote Payload, New Account With Lifecycle Hook, Install-time lifecycle script +2 more
Why PkgRadar flagged 2.0.0
| Severity | Signal | Evidence |
|---|---|---|
| high | New Lifecycle Script Vs Previous | package.json |
| medium | Remote Payload | package/lib/Utils/generics.js |
| medium | New Account With Lifecycle Hook | package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.0 | Review | 9 | 2026-06-25 |
2.0.0 | High risk | 62 | 2026-06-25 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm @ayunlove/[email protected]