PkgRadar

npm · registry.npmjs.org

@ceraph/react-native-mcp

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{var e=process.env;if(e.CI||e.CERAPH_SKIP_POSTINSTALL||require('fs').existsSync(process.cwd()+'/../../pnpm-workspace.yaml'))process.exit(0);process.stderr.write('\\n[@ceraph/react-native-mcp] installed. To finish setup run: npx @ceraph/react-native-mcp init\\n (MCP config, sign-in, the runtime-error hook, and your Mac LAN IP. Build/run/device tools work without it.)\\n\\n')}catch(_){}\""

Why PkgRadar flagged 0.4.1

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.4.1 vs 0.3.3: "node -e \"try{var e=process.env;if(e.CI||e.CERAPH_SKIP_POSTINSTALL||require('fs').existsSync(process.cwd()+'/../../pnpm-workspace.yaml'))process.exit(0);process.stderr.write('\\n[@ceraph/react-native-mcp] installed. To finish setup run: npx @ceraph/react-native-mcp init\\n (MCP config, sign-in, the runtime-error hook, and your Mac LAN IP. Build/run/device tools work without it.)\\n\\n')}catch(_){}\"" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{var e=process.env;if(e.CI||e.CERAPH_SKIP_POSTINSTALL||require('fs').existsSync(process.cwd()+'/../../pnpm-workspace.yaml'))process.exit(0);process.stderr.write('\\n[@ceraph/react-native-mcp] installed. To finish setup run: npx @ceraph/react-native-mcp init\\n (MCP config, sign-in, the runtime-error hook, and your Mac LAN IP. Build/run/device tools work without it.)\\n\\n')}catch(_){}\"" · package.json
mediumNew Account With Lifecycle Hookpackage first published 35 day(s) ago, 7 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.1High risk802026-06-16
0.4.0High risk802026-06-16
0.3.3Low risk02026-06-11
0.3.2Low risk02026-06-11
0.3.1Low risk02026-06-11
0.3.0Low risk02026-06-11
0.2.0Low risk02026-06-09
0.2.2Low risk02026-06-09
0.2.1Low risk02026-06-09

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @ceraph/react-native-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ceraph/[email protected]