PkgRadar

npm · registry.npmjs.org

@customerio/cli

Install-time lifecycle script: postinstall="node .npm/postinstall.js"

Why PkgRadar flagged 0.0.18

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.0.18 vs 0.0.18-alpha.1: "node .npm/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.18High risk452026-06-18
0.0.18-alpha.1Low risk02026-06-18
0.0.17Review12026-06-18
0.0.17-alpha.2Review12026-06-18
0.0.16Review12026-06-18
0.0.17-alpha.1Review12026-06-18
0.0.16-alpha.1High risk452026-06-17
0.0.15Low risk02026-06-17
0.0.14Low risk02026-06-16
0.0.12Low risk02026-06-15
0.0.13Low risk02026-06-15
0.0.11Low risk02026-06-12
0.0.10Low risk02026-06-11
0.0.9Low risk02026-06-09
0.0.8Low risk02026-06-05
0.0.7Low risk02026-06-02
0.0.5Low risk02026-05-29
0.0.6Low risk02026-05-29

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @customerio/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @customerio/[email protected]