PkgRadar

npm · registry.npmjs.org

@vishwalab/cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"var fs=require('fs');var p='node_modules/rpc-websockets/node_modules/uuid';if(fs.existsSync(p)){try{var v=parseInt(require('./'+p+'/package.json').version);if(v>8){fs.rmSync(p,{recursive:true});console.log('[vishwa-cli] Removed incompatible nested uuid@v'+v)}}catch(e){}}\""

Why PkgRadar flagged 0.0.1-beta.22

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"var fs=require('fs');var p='node_modules/rpc-websockets/node_modules/uuid';if(fs.existsSync(p)){try{var v=parseInt(require('./'+p+'/package.json').version);if(v>8){fs.rmSync(p,{recursive:true});console.log('[vishwa-cli] Removed incompatible nested uuid@v'+v)}}catch(e){}}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.1-beta.0Low risk02026-06-13
0.0.1-beta.22High risk352026-06-13
0.0.1-beta.3Low risk02026-06-13
0.0.1-beta.12High risk352026-06-10
0.0.1-beta.13High risk352026-06-10
0.0.1-beta.11High risk352026-06-10
0.0.1-beta.10High risk352026-06-10
0.0.1-beta.21High risk352026-06-10
0.0.1-beta.20High risk352026-06-10
0.0.1-beta.19High risk352026-06-10
0.0.1-beta.18High risk352026-06-10
0.0.1-beta.17High risk352026-06-10
0.0.1-beta.16High risk352026-06-10
0.0.1-beta.15High risk352026-06-10

Block this in CI

PkgRadar gates @vishwalab/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @vishwalab/[email protected]