PkgRadar

npm · registry.npmjs.org

@periskope/baileys

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 7.0.0-rc13-alpha-6

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 7.0.0-rc13-alpha-6 vs 7.0.0-rc13-alpha-5: "patch-package" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/Utils/generics.js

Scanned versions

VersionVerdictScoreScanned (UTC)
7.0.0-rc13-alpha-6High risk622026-06-10
7.0.0-rc13-alpha-7Review82026-05-31
7.0.0-rc13-alpha-4Review82026-05-30
7.0.0-rc13-alpha-5Review82026-05-30
7.0.0-rc13-alpha-2Review82026-05-30
7.0.0-rc13-alpha-3Review82026-05-30

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @periskope/baileys (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @periskope/[email protected]