PkgRadar

npm · registry.npmjs.org

@halfagiraf/clawx

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('fs').chmodSync('bin/clawx.js',0o755)}catch{}\""

Why PkgRadar flagged 0.9.65

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('fs').chmodSync('bin/clawx.js',0o755)}catch{}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.65High risk352026-06-16
0.9.64High risk352026-06-16
0.9.63High risk352026-06-16
0.9.62High risk352026-06-16
0.9.61High risk352026-06-16
0.9.60High risk752026-06-16
0.9.59Low risk02026-06-16
0.9.12Low risk02026-06-16
0.9.13Low risk02026-06-16
0.9.58Low risk02026-06-16
0.9.57Low risk02026-06-16
0.9.56Low risk02026-06-16
0.9.55Low risk02026-06-16

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @halfagiraf/clawx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @halfagiraf/[email protected]