PkgRadar

npm · registry.npmjs.org

@tom2012/cc-web

Install Lifecycle Suppresses Failure: postinstall="npx electron-builder install-app-deps || true"

Why PkgRadar flagged 2026.6.13-e

SeveritySignalEvidence
highInstall Lifecycle Suppresses Failurepostinstall="npx electron-builder install-app-deps || true" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/backend/dist/routes/update.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.13-eHigh risk522026-06-13
2026.6.13-dHigh risk522026-06-13
2026.6.13-cHigh risk522026-06-13
2026.6.13-bHigh risk402026-06-13
2026.6.13-aHigh risk402026-06-12
2026.6.12-cHigh risk402026-06-12
2026.6.12-bHigh risk402026-06-12
2026.6.12-aHigh risk402026-06-12
2026.5.24-hHigh risk402026-06-10
2026.6.8-aHigh risk402026-06-10
2026.5.24-aHigh risk402026-06-10
2026.5.24-fHigh risk402026-06-10
2026.5.24-eHigh risk402026-06-10
2026.5.24-gHigh risk402026-06-10
2026.5.24-cHigh risk402026-06-10
2026.5.24-iHigh risk402026-06-10
2026.5.24-dHigh risk402026-06-10
2026.5.24-bHigh risk402026-06-10
2026.5.24-jHigh risk402026-06-10

Block this in CI

PkgRadar gates @tom2012/cc-web (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @tom2012/[email protected]