PkgRadar

npm · registry.npmjs.org

@slycode/slycode

Install Lifecycle Remote Or Exec: postinstall="node -e \"const fs=require('fs'),p=require('path'); try{const d=p.join(p.dirname(require.resolve('node-pty/package.json')),'prebuilds'); fs.readdirSync(d).filter(f=>f.startsWith('darwin')).forEach(f=>{const h=p.join(d,f,'spawn-helper'); if(fs.existsSync(h)){fs.chmodSync(h,0o755);console.log('[slycode] Fixed node-pty spawn-helper permissions:',h)}})}catch{}\""

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('fs'),p=require('path'); try{const d=p.join(p.dirname(require.resolve('node-pty/package.json')),'prebuilds'); fs.readdirSync(d).filter(f=>f.startsWith('darwin')).forEach(f=>{const h=p.join(d,f,'spawn-helper'); if(fs.existsSync(h)){fs.chmodSync(h,0o755);console.log('[slycode] Fixed node-pty spawn-helper permissions:',h)}})}catch{}\"" · package.json
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/dist/web/node_modules/next/dist/lib/mkcert.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/messaging/channels/telegram.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1High risk1052026-06-13
0.2.39High risk1052026-06-13
0.2.40High risk1052026-06-13
0.3.0High risk1052026-06-13
0.2.38High risk1052026-06-13

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @slycode/slycode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @slycode/[email protected]
@slycode/slycode — npm security scan | PkgRadar