PkgRadar

npm · registry.npmjs.org

@ngocsangairvds/vsaf

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 4.2.11

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/skills/vds-skill/install-deps.mjs
mediumRemote Payloadmatched "curl " · package/skills/vds-skill/install-deps.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
4.2.11High risk432026-06-12
4.2.10High risk432026-06-12
4.1.31High risk432026-06-10
4.1.29High risk432026-06-10
4.1.30High risk432026-06-10
4.1.26High risk432026-06-10
4.1.25High risk432026-06-10
4.1.23High risk432026-06-10
4.1.22High risk432026-06-10
4.1.14High risk432026-06-10
4.1.12High risk432026-06-10
4.1.3High risk352026-06-10
4.1.4High risk352026-06-10
4.1.1High risk502026-06-10
4.1.0High risk502026-06-10
4.2.9High risk432026-06-10
4.2.8High risk622026-06-10
4.2.7High risk432026-06-10
4.2.6High risk622026-06-10
4.2.5High risk622026-06-10
4.2.4High risk622026-06-10
4.2.3High risk432026-06-10
4.2.2High risk432026-06-10
4.2.1High risk432026-06-10
4.2.0High risk622026-06-10
4.2.0-preview.0High risk622026-06-10
4.0.17High risk502026-06-10
4.0.16High risk502026-06-10
4.2.0-preview.1High risk432026-06-01

Block this in CI

PkgRadar gates @ngocsangairvds/vsaf (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ngocsangairvds/[email protected]