PkgRadar

npm · registry.npmjs.org

@pushary/agent-hooks

Js Obfuscated Fetch Exec: Hex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection).

Why PkgRadar flagged 0.18.3

SeveritySignalEvidence
highJs Obfuscated Fetch ExecHex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection). · package/dist/bin/pushary-setup.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.18.3High risk452026-06-20
0.18.2High risk452026-06-20
0.18.0Low risk02026-06-19
0.18.1Low risk02026-06-19
0.17.0Low risk02026-06-14
0.16.0Low risk02026-06-11
0.14.4Low risk02026-06-09
0.15.0Low risk02026-06-09
0.14.3Low risk02026-06-09
0.14.2Low risk02026-06-09
0.14.1Low risk02026-06-08
0.14.0Low risk02026-06-07
0.13.0Low risk02026-06-07
0.12.0Low risk02026-06-03
0.11.1Low risk02026-05-31
0.11.0Low risk02026-05-31
0.10.1Low risk02026-05-31
0.10.0Low risk02026-05-31
0.9.1Low risk02026-05-31
0.8.3Low risk02026-05-31
0.9.0Low risk02026-05-31

Block this in CI

PkgRadar gates @pushary/agent-hooks (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @pushary/[email protected]