PkgRadar

npm · registry.npmjs.org

@gstack-vibehard/installer

Remote Payload: matched "iwr "

Why PkgRadar flagged 2.1.8

SeveritySignalEvidence
mediumRemote Payloadmatched "iwr " · package/src/installer/install.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.8Review122026-06-09
2.1.7Review122026-06-09
2.1.6Review122026-06-09
2.1.5Review122026-06-09
2.1.4Review122026-06-09
2.1.3Review122026-06-09
2.1.2Review122026-06-09
2.1.1Review122026-06-09
2.1.0Review122026-06-09
2.0.5Review622026-06-09
2.0.4Review622026-06-09
2.0.3Review622026-06-09
2.0.2Review622026-06-09
2.0.1Review572026-06-08
2.0.0Review572026-06-08
0.7.4Review572026-06-04
0.7.5Review572026-06-04
0.7.2Review572026-06-03
0.7.3Review572026-06-03

Block this in CI

PkgRadar gates @gstack-vibehard/installer (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gstack-vibehard/[email protected]