PkgRadar

npm · registry.npmjs.org

@nano-step/nano-brain

Install-time lifecycle script: postinstall="node npm/postinstall.js"

Why PkgRadar flagged 2026.5.25-beta.25

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2026.5.25-beta.25 vs 2026.1.14: "node npm/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.1301Review32026-06-13
2026.6.1101Review32026-06-11
2026.6.1001Review32026-06-10
2026.5.25-beta.25High risk452026-06-10
2026.6.903Review32026-06-09
2026.6.902Review32026-06-09
2026.6.901Review32026-06-09
2026.6.705Review32026-06-07
2026.6.704Review32026-06-07
2026.6.702Review32026-06-07
2026.6.703Review32026-06-07
2026.6.701Review32026-06-07
2026.6.606Review32026-06-06
2026.6.605Review52026-06-06
2026.6.604Review32026-06-06
2026.6.603Review32026-06-06
2026.6.602Review32026-06-06
2026.6.601Review32026-06-06
2026.6.512Review32026-06-05
2026.6.510Review32026-06-05
2026.6.511Review52026-06-05
2026.6.504Review32026-06-05
2026.6.503Review32026-06-05
2026.6.502Review32026-06-05
2026.6.501Review32026-06-05
2026.6.403Review32026-06-04
2026.6.404Review52026-06-04
2026.6.401Review32026-06-04
2026.6.314Review52026-06-03
2026.6.313Review52026-06-03
2026.6.311Review32026-06-03
2026.6.310Review52026-06-03
2026.6.309Review32026-06-03
2026.6.308Review32026-06-03
2026.6.307Review32026-06-03
2026.6.306Review32026-06-03
2026.6.305Review32026-06-03
2026.6.304Review32026-06-03
2026.6.303Review32026-06-03
2026.6.302Review32026-06-03
2026.6.301Review32026-06-03
2026.6.209Review52026-06-02
2026.6.207Review32026-06-02
2026.6.208Review32026-06-02
2026.6.205Review32026-06-02
2026.6.204Review32026-06-02
2026.6.203Review52026-06-02
2026.6.202Review32026-06-02
2026.6.201Review32026-06-02
2026.6.107Review52026-06-01
2026.6.108Review52026-06-01
2026.6.105Review52026-06-01
2026.6.104Review52026-06-01
2026.6.103Review52026-06-01
2026.6.102Review32026-06-01
2026.6.101Review52026-06-01
2026.6.8Review32026-06-01
2026.6.6Review52026-06-01
2026.6.7Review52026-06-01
2026.6.5Review32026-06-01
2026.6.4Review32026-06-01
2026.6.3Review52026-06-01
2026.5.3105Review52026-05-31
2026.5.3104Review32026-05-31
2026.5.3103Review32026-05-31
2026.5.3102Review32026-05-31
2026.5.3101Review32026-05-31
2026.5.2902Review32026-05-30
2026.5.2901Review32026-05-30
2026.5.2715Review32026-05-30
2026.5.2713Review52026-05-30
2026.5.2714Review32026-05-30
2026.5.3008Review52026-05-30
2026.5.3007Review32026-05-30
2026.5.267Review52026-05-30
2026.5.266Review52026-05-30
2026.5.265Review52026-05-30
2026.5.264Review52026-05-30
2026.5.263Review52026-05-30
2026.5.262Review32026-05-30
2026.5.261Review32026-05-30
2026.5.26Review32026-05-30
2026.5.25-beta.31Review32026-05-30
2026.5.25-beta.30Review52026-05-30
2.0.0-beta.6Review52026-05-30
2026.5.30Review32026-05-30
2026.5.3006Review32026-05-30
2026.5.3004Review32026-05-30
2026.5.2903Review32026-05-30
2026.1.14Low risk02026-05-25

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @nano-step/nano-brain (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nano-step/[email protected]