PkgRadar

npm · registry.npmjs.org

@exulu/backend

Install Lifecycle Remote Or Exec: preinstall="node -e \"if (process.version !== 'v22.18.0') { console.error('❌ Wrong Node.js version. Expected v22.18.0, got ' + process.version); process.exit(1); }\""

Why PkgRadar flagged 1.60.0

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpreinstall="node -e \"if (process.version !== 'v22.18.0') { console.error('❌ Wrong Node.js version. Expected v22.18.0, got ' + process.version); process.exit(1); }\"" · package.json
mediumRemote Payloadmatched "curl " · package/ee/python/setup.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.60.0High risk262026-06-10
1.58.0High risk262026-06-10
1.59.0High risk262026-06-10
1.66.0High risk262026-06-10
1.65.0High risk262026-06-10
1.64.0High risk262026-06-10
1.63.3High risk262026-06-10
1.63.2High risk262026-06-10
1.63.1High risk262026-06-10
1.63.0High risk262026-06-10
1.62.1High risk262026-06-10
1.62.0High risk262026-06-10
1.61.3High risk262026-06-10
1.61.2High risk262026-06-10
1.61.1High risk262026-06-10
1.61.0High risk262026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @exulu/backend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @exulu/[email protected]