npm · registry.npmjs.org
@cnbattle/pi-web
Reverse Shell, Suspicious Publish Context
Why PkgRadar flagged 0.7.5
| Severity | Signal | Evidence |
|---|---|---|
| high | Reverse Shell | package/.next/static/chunks/2156-edc7ff6b1b32367a.js |
| medium | Suspicious Publish Context | — |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.7.5 | High risk | 50 | 2026-06-23 |
0.7.4 | High risk | 50 | 2026-06-23 |
0.7.3 | High risk | 50 | 2026-06-23 |
0.7.1 | High risk | 50 | 2026-06-23 |
0.7.2 | High risk | 50 | 2026-06-23 |
0.7.0 | High risk | 50 | 2026-06-23 |
Block this in CI
pkgradar gate --ecosystem npm @cnbattle/[email protected]