PkgRadar

npm · registry.npmjs.org

@wendongfly/myhi

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('fs').chmodSync(require('path').join(__dirname,'bin','myhi.js'),0o755)}catch(e){}\""

Why PkgRadar flagged 1.3.75

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('fs').chmodSync(require('path').join(__dirname,'bin','myhi.js'),0o755)}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.75High risk352026-06-13
1.3.76High risk352026-06-13
1.3.74High risk242026-06-10
1.3.72High risk352026-06-10
1.3.73High risk242026-06-10
1.3.64High risk242026-06-10
1.3.63High risk282026-06-10
1.3.78High risk242026-06-10
1.3.77High risk242026-06-10
1.3.62High risk242026-06-10
1.3.61High risk242026-06-10
1.3.60High risk242026-06-10
1.3.57High risk242026-06-10
1.3.58High risk242026-06-10
1.3.55High risk242026-06-10
1.3.56High risk242026-06-10

Related campaigns

Block this in CI

PkgRadar gates @wendongfly/myhi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @wendongfly/[email protected]