PkgRadar

npm · registry.npmjs.org

@jykim0507/hd-map

Install Lifecycle Remote Or Exec: postinstall="node -e \"const fs=require('fs'),path=require('path');const src=path.join(__dirname,'public');const dest=path.join(process.env.INIT_CWD,'public');fs.mkdirSync(path.join(dest,'geojson'),{recursive:true});fs.copyFileSync(path.join(src,'output.pmtiles'),path.join(dest,'output.pmtiles'));fs.copyFileSync(path.join(src,'geojson/a2_link.geojson'),path.join(dest,'geojson/a2_link.geojson'));fs.copyFileSync(path.join(src,'geojson/b1_safetysign.geojson'),path.join(dest,'geojson/b1_safetysign.geojson'));fs.copyFileSync(path.join(src,'geojson/b3_surfacemark.geojson'),path.join(dest,'geojson/b3_surfacemark.geojson'))\""

Why PkgRadar flagged 0.0.135

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('fs'),path=require('path');const src=path.join(__dirname,'public');const dest=path.join(process.env.INIT_CWD,'public');fs.mkdirSync(path.join(dest,'geojson'),{recursive:true});fs.copyFileSync(path.join(src,'output.pmtiles'),path.join(dest,'output.pmtiles'));fs.copyFileSync(path.join(src,'geojson/a2_link.geojson'),path.join(dest,'geojson/a2_link.geojson'));fs.copyFileSync(path.join(src,'geojson/b1_safetysign.geojson'),path.join(dest,'geojson/b1_safetysign.geojson'));fs.copyFileSync(path.join(src,'geojson/b3_surfacemark.geojson'),path.join(dest,'geojson/b3_surfacemark.geojson'))\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.135High risk352026-06-10
0.0.134High risk242026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @jykim0507/hd-map (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jykim0507/[email protected]