PkgRadar

npm · registry.npmjs.org

deepv-code

Install Lifecycle Remote Or Exec: postinstall="node -e \"const fs = require('fs'); const path = 'bundle/fix-binary-permissions.js'; if (fs.existsSync(path)) { require('child_process').execSync('node ' + path + ' --all', {stdio: 'inherit'}); } else { console.log('⏭\u{fe0f} Skipping binary permissions fix (bundle not built yet)'); }\""

Why PkgRadar flagged 1.0.368

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs = require('fs'); const path = 'bundle/fix-binary-permissions.js'; if (fs.existsSync(path)) { require('child_process').execSync('node ' + path + ' --all', {stdio: 'inherit'}); } else { console.log('⏭\u{fe0f} Skipping binary permissions fix (bundle not built yet)'); }\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.368High risk242026-06-13
1.0.367High risk242026-06-13
1.0.366High risk242026-06-13
1.0.365High risk242026-06-13
1.0.364High risk242026-06-13
1.0.362High risk242026-06-13
1.0.361High risk242026-06-13
1.0.359High risk242026-06-10
1.0.358High risk242026-06-10
1.0.357High risk242026-06-10
1.0.355High risk242026-06-10
1.0.354High risk242026-06-10
1.0.353High risk242026-06-10
1.0.352High risk242026-06-10
1.0.349High risk242026-06-10
1.0.348High risk242026-06-10
1.0.347High risk242026-06-10
1.0.345High risk242026-06-10
1.0.346High risk242026-06-10
1.0.344High risk242026-06-10
1.1.1High risk242026-06-10
1.0.399High risk242026-06-10
1.0.398High risk242026-06-10
1.0.397High risk242026-06-10
1.0.396High risk242026-06-10
1.0.395High risk242026-06-10
1.0.394High risk242026-06-10
1.0.393High risk242026-06-10
1.0.392High risk242026-06-10
1.0.391High risk242026-06-10
1.0.389High risk242026-06-10
1.0.388High risk242026-06-10
1.0.387High risk352026-06-10
1.0.382High risk242026-06-10
1.0.381High risk242026-06-10
1.0.380High risk242026-06-10
1.0.379High risk242026-06-10
1.0.378High risk242026-06-10
1.0.377High risk242026-06-10
1.0.376High risk242026-06-10
1.0.375High risk242026-06-10
1.0.343High risk242026-06-10
1.0.342High risk242026-06-10
1.0.374High risk242026-06-10
1.0.373High risk242026-06-10
1.0.372High risk242026-06-10
1.0.371High risk242026-06-10
1.0.370High risk242026-06-10
1.0.369High risk242026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates deepv-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]