PkgRadar

npm · registry.npmjs.org

codeam-cli

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 2.39.27

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/index.js
highInstall Lifecycle Suppresses Failurepostinstall="node dist/postinstall.js || true" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.39.27High risk492026-06-17
2.39.26High risk492026-06-17
2.39.24High risk492026-06-17
2.39.25High risk492026-06-17
2.39.23High risk492026-06-17
2.39.22High risk492026-06-16
2.39.21High risk492026-06-16
2.39.20High risk492026-06-15
2.39.19High risk492026-06-15
2.39.18High risk492026-06-14
2.39.17High risk492026-06-14
2.39.16High risk492026-06-14
2.39.15High risk492026-06-14
2.39.14High risk492026-06-14
2.39.13High risk492026-06-14
2.39.12High risk352026-06-13
2.39.11High risk352026-06-13
2.39.10High risk352026-06-13
2.39.9High risk352026-06-13
2.39.8High risk352026-06-13
2.39.7High risk352026-06-13
2.39.6High risk352026-06-13
2.39.5High risk352026-06-13
2.39.4High risk352026-06-12
2.39.3High risk352026-06-12
2.39.2High risk352026-06-12
2.39.1High risk352026-06-12
2.39.0High risk352026-06-12
2.38.0High risk352026-06-12
2.37.3High risk492026-06-11
2.37.2High risk492026-06-11
2.37.1High risk492026-06-11
2.37.0High risk492026-06-11
2.36.5High risk492026-06-11
2.36.4High risk492026-06-11
2.36.2High risk492026-06-11
2.36.3High risk492026-06-11
2.36.0High risk492026-06-11
2.36.1High risk492026-06-11
2.35.9High risk492026-06-11
2.35.8High risk492026-06-10
2.35.7High risk492026-06-10
2.35.6High risk492026-06-10
2.35.5High risk492026-06-10
2.35.4High risk492026-06-10
2.35.2High risk492026-06-10
2.35.3High risk492026-06-10
2.35.1High risk492026-06-10
2.35.0High risk492026-06-10
2.23.18High risk492026-06-10
2.23.16High risk702026-06-10
2.23.17High risk702026-06-10
2.23.13High risk702026-06-10
2.23.14High risk492026-06-10
2.23.10High risk492026-06-10
2.23.8High risk702026-06-10
2.23.9High risk492026-06-10
2.23.5High risk492026-06-10
2.34.0High risk492026-06-10
2.33.0High risk702026-06-10
2.32.10High risk702026-06-10
2.32.9High risk492026-06-10
2.32.8High risk702026-06-10
2.32.7High risk492026-06-10
2.32.6High risk492026-06-10
2.32.5High risk702026-06-10
2.32.4High risk702026-06-10
2.32.3High risk702026-06-10
2.32.2High risk702026-06-10
2.32.1High risk492026-06-10
2.32.0High risk492026-06-10
2.31.0High risk492026-06-10
2.30.0High risk492026-06-10
2.29.0High risk492026-06-10
2.28.1High risk492026-06-10
2.28.0High risk492026-06-10
2.27.16High risk492026-06-10
2.27.15High risk492026-06-10
2.27.14High risk492026-06-10
2.27.13High risk492026-06-10
2.27.12High risk492026-06-10
2.27.11High risk492026-06-10
2.27.10High risk492026-06-10
2.27.9High risk492026-06-10
2.27.7High risk702026-06-10
2.27.8High risk492026-06-10
2.27.5High risk492026-06-10
2.27.6High risk702026-06-10
2.27.4High risk702026-06-10
2.27.3High risk702026-06-10
2.27.2High risk492026-06-10
2.27.1High risk702026-06-10
2.27.0High risk492026-06-10
2.26.16High risk492026-06-10
2.26.15High risk492026-06-10
2.26.14High risk702026-06-10
2.26.12High risk702026-06-10
2.26.13High risk702026-06-10
2.26.10High risk492026-06-10
2.26.11High risk492026-06-10
2.26.4High risk702026-06-10
2.26.5High risk492026-06-10
2.25.0High risk492026-06-10
2.24.0High risk492026-06-10
2.23.37High risk492026-06-10
2.23.36High risk492026-06-10
2.23.34High risk492026-06-10
2.23.35High risk492026-06-10
2.23.33High risk492026-06-10
2.23.32High risk492026-06-10
2.23.31High risk492026-06-10
2.23.30High risk492026-06-10
2.23.29High risk492026-06-10
2.23.28High risk492026-06-10
2.23.27High risk492026-06-10
2.23.26High risk492026-06-10
2.23.25High risk492026-06-10
2.23.24High risk492026-06-10
2.23.23High risk492026-06-10
2.23.22High risk492026-06-10
2.23.21High risk492026-06-10
2.23.20High risk492026-06-10
2.23.4High risk492026-06-10
2.23.3High risk492026-06-10
2.23.0High risk492026-06-10
2.23.1High risk492026-06-10
2.22.0High risk492026-06-10
2.22.1High risk492026-06-10
2.21.2High risk492026-06-10
2.23.19High risk702026-06-10
2.19.0High risk492026-06-10
2.18.2High risk702026-06-10
2.21.0High risk702026-06-10
2.20.2High risk702026-06-10
2.21.1High risk702026-06-10
2.20.0High risk492026-06-10
2.20.3High risk492026-06-10
2.18.1High risk702026-06-10
2.20.1High risk702026-06-10

Block this in CI

PkgRadar gates codeam-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]