PkgRadar

npm · registry.npmjs.org

@su-record/vibe

Install Lifecycle Remote Or Exec: postinstall="node -e \"import('./dist/cli/postinstall/main.js').then(m=>m.main()).catch(()=>{})\""

Why PkgRadar flagged 2.12.3

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"import('./dist/cli/postinstall/main.js').then(m=>m.main()).catch(()=>{})\"" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/infra/lib/gpt/chat.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.12.3High risk322026-06-13
2.14.1High risk322026-06-11
2.14.0High risk322026-06-11
2.13.0High risk322026-06-11
2.12.2High risk322026-06-10
2.12.1High risk322026-06-10
2.11.0High risk322026-06-10
2.10.2High risk322026-06-10
2.12.5High risk322026-06-10
2.12.4High risk322026-06-10
1.3.0Review82026-06-10
1.3.4Review82026-06-10
1.3.2Review82026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates @su-record/vibe (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @su-record/[email protected]