PkgRadar

npm · registry.npmjs.org

clawbridge-codex

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('better-sqlite3')}catch(e){console.error('\\n⚠ ClawBridge needs build tools for the database driver.\\nRun: apt install -y python3 make g++ (Ubuntu/Debian) or yum install -y python3 make gcc-c++ (CentOS)\\nThen: npm install -g clawbridge-codex\\n')}\""

Why PkgRadar flagged 2.11.4

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('better-sqlite3')}catch(e){console.error('\\n⚠ ClawBridge needs build tools for the database driver.\\nRun: apt install -y python3 make g++ (Ubuntu/Debian) or yum install -y python3 make gcc-c++ (CentOS)\\nThen: npm install -g clawbridge-codex\\n')}\"" · package.json
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/shared/admin-alert.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/doctor.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/error-handler.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/setup/index.js
mediumRemote Payloadmatched "curl " · package/setup/add-telegram.sh
mediumRemote Payloadmatched "curl " · package/setup/lib/diagnostics.sh
mediumRemote Payloadmatched "api.telegram.org/bot" · package/setup/channels/telegram.ts
mediumNew Account With Lifecycle Hookpackage first published 26 day(s) ago, 9 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.11.4High risk1492026-06-10
2.11.1High risk1892026-06-10
2.10.0High risk1892026-06-10
2.9.10High risk1892026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates clawbridge-codex (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]