PkgRadar

npm · registry.npmjs.org

@pokeme/cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{var p=require('path'),f=require('fs'),h=p.join(require.resolve('node-pty/package.json'),'..','prebuilds',process.platform+'-'+process.arch,'spawn-helper');if(f.existsSync(h))f.chmodSync(h,0o755)}catch(e){}\""

Why PkgRadar flagged 0.1.6

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{var p=require('path'),f=require('fs'),h=p.join(require.resolve('node-pty/package.json'),'..','prebuilds',process.platform+'-'+process.arch,'spawn-helper');if(f.existsSync(h))f.chmodSync(h,0o755)}catch(e){}\"" · package.json
mediumNew Account With Lifecycle Hookpackage first published 62 day(s) ago, 8 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.6High risk352026-06-10
0.1.7High risk802026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @pokeme/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pokeme/[email protected]