PkgRadar

npm · registry.npmjs.org

@openjobs/cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"const fs=require('fs'),p=require('path'),d=process.cwd(); if (!d.includes('node_modules')) process.exit(0); const missing=[]; for (const rel of ['dist/bin.cjs','skill/SKILL.md']) { if (!fs.existsSync(p.join(d, rel))) missing.push(rel); } if (missing.length) { console.error('[@openjobs/cli] FATAL: bundled file(s) missing from this install: '+missing.join(', ')+'. This is a packaging bug — please report at https://github.com/openjobsagent/openjobs/issues and reinstall with: npm i -g @openjobs/cli@latest'); process.exit(1); }\""

Why PkgRadar flagged 3.1.2

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('fs'),p=require('path'),d=process.cwd(); if (!d.includes('node_modules')) process.exit(0); const missing=[]; for (const rel of ['dist/bin.cjs','skill/SKILL.md']) { if (!fs.existsSync(p.join(d, rel))) missing.push(rel); } if (missing.length) { console.error('[@openjobs/cli] FATAL: bundled file(s) missing from this install: '+missing.join(', ')+'. This is a packaging bug — please report at https://github.com/openjobsagent/openjobs/issues and reinstall with: npm i -g @openjobs/cli@latest'); process.exit(1); }\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.2High risk352026-06-13
3.1.1High risk352026-06-12
3.1.0High risk352026-06-11
3.0.3High risk352026-06-10
3.0.1High risk352026-06-10
2.7.0High risk352026-06-10
3.0.0High risk352026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @openjobs/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @openjobs/[email protected]