PkgRadar

npm · registry.npmjs.org

@npo/player

Install Lifecycle Remote Or Exec: postinstall="node -e \"var p=require('path'),f=require('fs'),d=p.join('node_modules','shaka-player','dist');try{f.readdirSync(d).filter(x=>x.endsWith('.d.ts')).forEach(x=>f.unlinkSync(p.join(d,x)))}catch(e){}\""

Why PkgRadar flagged 2.0.0-beta.1

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"var p=require('path'),f=require('fs'),d=p.join('node_modules','shaka-player','dist');try{f.readdirSync(d).filter(x=>x.endsWith('.d.ts')).forEach(x=>f.unlinkSync(p.join(d,x)))}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-beta.1High risk172026-06-09
2.0.0High risk172026-06-09
2.0.0-beta.2High risk172026-06-09
2.0.0-beta.3High risk172026-06-09

Block this in CI

PkgRadar gates @npo/player (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @npo/[email protected]