PkgRadar

npm · registry.npmjs.org

@huggingface/tasks

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 0.21.10

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/commonjs/local-apps.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/esm/local-apps.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/commonjs/local-apps.spec.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/esm/local-apps.spec.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/src/local-apps.spec.ts
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/src/local-apps.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.21.10Review152026-06-08
0.21.9Review152026-06-08
0.21.8Review152026-06-04
0.21.7Review152026-06-03
0.21.6Review152026-06-03
0.21.5Review152026-06-02
0.21.4Review152026-06-01
0.21.3Review152026-06-01
0.21.1Low risk02026-05-27
0.21.2Low risk02026-05-27

Block this in CI

PkgRadar gates @huggingface/tasks (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @huggingface/[email protected]