npm · registry.npmjs.org
@brandon_9527/tcode
Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.
Why PkgRadar flagged 1.0.6
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Hidden Powershell | Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/src/build-python.js |
| high | Credential File Packaged | package/dist/python-src/.env · package/dist/python-src/.env |
| high | Install Lifecycle Remote Or Exec | install="node -e \"import('./dist/src/build-python.js').then(m => m.build())\"" · package.json |
| medium | Remote Payload | matched "curl " · package/dist/python-src/_workspace/install.sh |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.6 | High risk | 127 | 2026-06-14 |
1.0.7 | High risk | 127 | 2026-06-14 |
1.0.8 | High risk | 127 | 2026-06-14 |
1.0.9 | High risk | 127 | 2026-06-14 |
Campaign attribution
Related campaigns
- js_hidden_powershell:hidden / non-interactive powershell invocation in package code — `-windowstyle hidden`, `irm | iex`, `windowshide: true`, or equivalent — used to download-and-run payloads on windows installers. — 452 releases, max score 266
- brandon_9527 — 4 releases, max score 127
Block this in CI
pkgradar gate --ecosystem npm @brandon_9527/[email protected]