PkgRadar

npm · registry.npmjs.org

@rdk-moss/agent

Install Lifecycle Remote Or Exec: postinstall="node -e \"const fs=require('fs');try{fs.chmodSync('dist/cli.js',0o755)}catch{}\""

Why PkgRadar flagged 0.3.35

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('fs');try{fs.chmodSync('dist/cli.js',0o755)}catch{}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.35High risk552026-06-11
0.3.34High risk552026-06-11
0.3.33High risk552026-06-10
0.3.32High risk552026-06-10
0.3.31High risk552026-06-10
0.3.30High risk552026-06-10
0.3.29High risk552026-06-10
0.3.28High risk552026-06-10
0.3.27High risk552026-06-10
0.3.26High risk452026-06-10
0.3.25High risk452026-06-10
0.3.24High risk452026-06-10
0.3.23High risk452026-06-10
0.3.22High risk452026-06-10
0.3.21High risk452026-06-10
0.3.20High risk452026-06-10
0.3.18High risk452026-06-10
0.3.17High risk452026-06-10
0.3.16High risk452026-06-10
0.3.15High risk452026-06-10
0.3.14High risk452026-06-10
0.3.13High risk452026-06-10
0.3.12High risk452026-06-10
0.3.11High risk452026-06-10
0.3.10High risk452026-06-10
0.3.9High risk452026-06-10
0.3.8High risk452026-06-10
0.3.7High risk852026-06-10
0.3.4Review102026-05-29
0.3.2Review102026-05-29
0.3.3Review102026-05-29
0.3.1Review102026-05-29

Block this in CI

PkgRadar gates @rdk-moss/agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @rdk-moss/[email protected]