PkgRadar

npm · registry.npmjs.org

@paypal/smart-payment-buttons-prerelease

Install-time lifecycle script: postinstall="npm_config_registry=https://npm.paypal.com npm install @paypalcorp/web --no-save --proxy='null' --https-proxy='null' || echo 'Unable to install cdnx cli tools'"

Why PkgRadar flagged 2.0.368

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.0.368 vs 2.0.249-alpha.0: "npm_config_registry=https://npm.paypal.com npm install @paypalcorp/web --no-save --proxy='null' --https-proxy='null' || echo 'Unable to install cdnx cli tools'" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.237-alpha.0Low risk02026-06-17
2.0.249-alpha.0Low risk02026-06-17
2.0.368High risk452026-06-17

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @paypal/smart-payment-buttons-prerelease (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @paypal/[email protected]