PkgRadar

npm · registry.npmjs.org

bingocode

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 1.1.172

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/src/tools/PowerShellTool/pathValidation.ts
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/src/utils/permissions/permissions.ts
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/src/utils/permissions/yoloClassifier.ts
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/utils/plugins/installCounts.ts
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/utils/releaseNotes.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.172High risk722026-06-13
1.1.156High risk722026-06-13
1.1.155High risk722026-06-13
1.1.154High risk722026-06-13
1.1.173High risk1042026-06-12
1.1.152High risk722026-06-10
1.1.153High risk722026-06-10
1.1.151High risk722026-06-10
1.1.149High risk1042026-06-10
1.1.150High risk722026-06-10
1.1.142High risk722026-06-10
1.1.144High risk722026-06-10
1.1.143High risk722026-06-10
1.1.137High risk722026-06-10
1.1.171High risk722026-06-10
1.1.170High risk722026-06-10
1.1.169High risk722026-06-10
1.1.168High risk722026-06-10
1.1.167High risk1042026-06-10
1.1.166High risk722026-06-10
1.1.165High risk722026-06-10
1.1.164High risk722026-06-10
1.1.163High risk722026-06-10
1.1.162High risk722026-06-10
1.1.161High risk722026-06-10
1.1.160High risk722026-06-10
1.1.159High risk722026-06-10
1.1.158High risk722026-06-10
1.1.157High risk722026-06-10
1.1.136High risk722026-06-10
1.1.131High risk722026-06-10
1.1.133High risk722026-06-10
1.1.132High risk722026-06-10
1.1.129High risk722026-06-10
1.1.135High risk722026-06-10
1.1.134High risk722026-06-10
1.1.130High risk722026-06-10

Block this in CI

PkgRadar gates bingocode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]