PkgRadar

npm · registry.npmjs.org

@onebrain-ai/cli

Remote Payload: matched "github.com/onebrain-ai/onebrain-cli/releases/download"

Why PkgRadar flagged 3.0.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/onebrain-ai/onebrain-cli/releases/download" · package/postinstall.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0Review172026-05-30
3.2.21Review52026-05-29
3.2.19Review52026-05-29
3.2.20Review52026-05-29
3.2.18Review52026-05-29
3.2.17Review142026-05-29
3.2.16Review142026-05-29
3.2.15Review142026-05-28
3.2.13Review142026-05-28
3.2.14Review142026-05-28
3.2.11Review142026-05-28
3.2.12Review142026-05-28
3.2.6Review142026-05-27
3.2.5Review142026-05-27
3.2.2Review142026-05-27
3.2.1Review142026-05-27
3.1.5Review142026-05-26
3.2.0Review142026-05-26
3.1.0Review142026-05-26

Block this in CI

PkgRadar gates @onebrain-ai/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @onebrain-ai/[email protected]