PkgRadar

npm · registry.npmjs.org

@zero-transfer/sdk

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('node:fs').accessSync('scripts/link-sdk.mjs');require('node:child_process').execSync('node scripts/link-sdk.mjs',{stdio:'inherit'})}catch(e){if(e.code!=='ENOENT')process.exit(1)}\""

Why PkgRadar flagged 0.4.2

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('node:fs').accessSync('scripts/link-sdk.mjs');require('node:child_process').execSync('node scripts/link-sdk.mjs',{stdio:'inherit'})}catch(e){if(e.code!=='ENOENT')process.exit(1)}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.2High risk352026-06-11
0.4.6High risk352026-06-11
0.4.7High risk352026-06-11
0.4.8High risk352026-06-11

Block this in CI

PkgRadar gates @zero-transfer/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zero-transfer/[email protected]
@zero-transfer/sdk — npm security scan | PkgRadar