npm · registry.npmjs.org
cast-code
Install Lifecycle Remote Or Exec: postinstall="node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\""
Why PkgRadar flagged 1.0.27
| Severity | Signal | Evidence |
|---|---|---|
| high | New Lifecycle Script Vs Previous | postinstall added in 1.0.27 vs 1.0.26: "node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\"" · package.json |
| high | Install Lifecycle Remote Or Exec | postinstall="node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\"" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.26 | Review | 5 | 2026-06-13 |
1.0.28 | Review | 5 | 2026-06-13 |
1.0.29 | Review | 5 | 2026-06-13 |
1.0.27 | High risk | 80 | 2026-06-13 |
Campaign attribution
Block this in CI
pkgradar gate --ecosystem npm [email protected]