PkgRadar

npm · registry.npmjs.org

cast-code

Install Lifecycle Remote Or Exec: postinstall="node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\""

Why PkgRadar flagged 1.0.27

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.0.27 vs 1.0.26: "node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\"" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node -e \"var f=require('fs'),p=require('path').join(process.cwd(),'node_modules','deepagents','node_modules','uuid');try{f.existsSync(p)&&f.rmSync(p,{recursive:true,force:true})}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.26Review52026-06-13
1.0.28Review52026-06-13
1.0.29Review52026-06-13
1.0.27High risk802026-06-13

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates cast-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]