PkgRadar

npm · registry.npmjs.org

chump-agent

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 0.0.35

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/app/runtime.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/app/update.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.35Review152026-06-12
0.0.38Review152026-06-03
0.0.37Review152026-06-01
0.0.36Review152026-06-01
0.0.34Review152026-05-29
0.0.33Review152026-05-29
0.0.32Review132026-05-28
0.0.31Review122026-05-25
0.0.29Review122026-05-24
0.0.30Review122026-05-24

Block this in CI

PkgRadar gates chump-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]