PkgRadar

npm · registry.npmjs.org

@shadowob/connector

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 1.1.50

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/browser.cjs
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/index.cjs
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/chunk-IPJPK6TR.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.50Review352026-06-12
1.1.49Review502026-06-10
1.1.48Review352026-06-10
1.1.47Review502026-06-09
1.1.46Review502026-06-08
1.1.45Review502026-06-08
1.1.44Review352026-06-08
1.1.43Review502026-06-08
1.1.42Review352026-06-08
1.1.41Review352026-06-08
1.1.40Review352026-06-08
1.1.39Review352026-06-08
1.1.38Review352026-06-07
1.1.37Review352026-06-07
1.1.36Review352026-06-07
1.1.35Review502026-06-07
1.1.34Review352026-06-07
1.1.33Review352026-06-07
1.1.32Review352026-06-07
1.1.31Review352026-06-07
1.1.30Review352026-06-07
1.1.29Review352026-06-07
1.1.28Review352026-06-06
1.1.27Review502026-06-04
1.1.26Review352026-06-04
1.1.25Review352026-06-04
1.1.24Review502026-06-03
1.1.23Review352026-06-03
1.1.22Review352026-06-03
1.1.21Review352026-06-02
1.1.19Review502026-06-01
1.1.20Review352026-06-01
1.1.18Review352026-06-01
1.1.17Review502026-05-31
1.1.16Review502026-05-31
1.1.15Review502026-05-31
1.1.14Review502026-05-31
1.1.13Review502026-05-31
1.1.12Review502026-05-31
1.1.11Review502026-05-31
1.1.10Review502026-05-31
1.1.9Review502026-05-31
1.1.7Low risk02026-05-31
1.1.8Review502026-05-31

Block this in CI

PkgRadar gates @shadowob/connector (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @shadowob/[email protected]