npm · registry.npmjs.org
@npo/player
Install Lifecycle Remote Or Exec: postinstall="node -e \"var p=require('path'),f=require('fs'),d=p.join('node_modules','shaka-player','dist');try{f.readdirSync(d).filter(x=>x.endsWith('.d.ts')).forEach(x=>f.unlinkSync(p.join(d,x)))}catch(e){}\""
Why PkgRadar flagged 2.0.0-beta.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"var p=require('path'),f=require('fs'),d=p.join('node_modules','shaka-player','dist');try{f.readdirSync(d).filter(x=>x.endsWith('.d.ts')).forEach(x=>f.unlinkSync(p.join(d,x)))}catch(e){}\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.0.0-beta.1 | High risk | 17 | 2026-06-09 |
2.0.0 | High risk | 17 | 2026-06-09 |
2.0.0-beta.2 | High risk | 17 | 2026-06-09 |
2.0.0-beta.3 | High risk | 17 | 2026-06-09 |
Block this in CI
pkgradar gate --ecosystem npm @npo/[email protected]