PkgRadar

npm · registry.npmjs.org

antigravity-gemini-bridge

Install Lifecycle Remote Or Exec: postinstall="node -e \"const p=require('path'),fs=require('fs');const d=p.join(__dirname,'node_modules','node-pty','prebuilds');['darwin-arm64','darwin-x64','linux-x64','linux-arm64'].forEach(a=>{try{fs.chmodSync(p.join(d,a,'spawn-helper'),0o755)}catch{}})\""

Why PkgRadar flagged 0.16.1

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const p=require('path'),fs=require('fs');const d=p.join(__dirname,'node_modules','node-pty','prebuilds');['darwin-arm64','darwin-x64','linux-x64','linux-arm64'].forEach(a=>{try{fs.chmodSync(p.join(d,a,'spawn-helper'),0o755)}catch{}})\"" · package.json
mediumRemote Payloadmatched "curl " · package/dist/gemini.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.16.1High risk472026-06-16
0.16.0High risk472026-06-16
0.15.0High risk472026-06-16
0.15.1High risk472026-06-16
0.14.0High risk472026-06-16
0.13.0High risk472026-06-16
0.12.0High risk472026-06-16
0.10.0High risk472026-06-16
0.11.0High risk472026-06-16
0.8.32Review122026-06-16
0.8.33Review122026-06-16
0.8.34Review122026-06-16
0.9.0High risk872026-06-16

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates antigravity-gemini-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]