npm · registry.npmjs.org
@panguard-ai/panguard
Install Lifecycle Remote Or Exec: postinstall="node -e \"console.log('\\n Panguard AI v' + require('./package.json').version + ' installed.\\n\\n Quick start:\\n pga Open interactive menu\\n pga up Start protection + dashboard\\n pga scan Scan your skills\\n pga audit <dir> Audit a skill before installing\\n\\n First time? Just run: pga\\n')\""
Why PkgRadar flagged 1.5.4
| Severity | Signal | Evidence |
|---|---|---|
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"console.log('\\n Panguard AI v' + require('./package.json').version + ' installed.\\n\\n Quick start:\\n pga Open interactive menu\\n pga up Start protection + dashboard\\n pga scan Scan your skills\\n pga audit <dir> Audit a skill before installing\\n\\n First time? Just run: pga\\n')\"" · package.json |
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/dist/cli/commands/audit.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.5.4 | High risk | 47 | 2026-06-14 |
1.5.5 | High risk | 47 | 2026-06-14 |
1.5.6 | High risk | 47 | 2026-06-14 |
1.6.0 | High risk | 47 | 2026-06-14 |
Campaign attribution
Related campaigns
- panguard0414 — 14 releases, max score 266
Block this in CI
pkgradar gate --ecosystem npm @panguard-ai/[email protected]