PkgRadar

npm · registry.npmjs.org

@senlabsai/aigon

Install Lifecycle Suppresses Failure: postinstall="node ./aigon-cli.js global-setup --non-interactive --quiet || true && node scripts/fix-node-pty-perms.js || true && node ./aigon-cli.js installed-notice || true"

Why PkgRadar flagged 2.66.0-beta.4

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="node ./aigon-cli.js global-setup --non-interactive --quiet || true && node scripts/fix-node-pty-perms.js || true && node ./aigon-cli.js installed-notice || true" · package.json
mediumRemote Payloadmatched "curl " · package/lib/proxy.js
mediumNew Account With Lifecycle Hookpackage first published 33 day(s) ago, 9 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.66.0-beta.4High risk372026-06-10
2.66.0-beta.2High risk372026-06-10
2.66.0-beta.3High risk372026-06-10

Block this in CI

PkgRadar gates @senlabsai/aigon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @senlabsai/[email protected]