PkgRadar

npm · registry.npmjs.org

dttfdsdee

Install Lifecycle Dns Or Oast, New Account With Lifecycle Hook, Install-time lifecycle script

Early detection

PkgRadar flagged this 1h before public disclosure

Detected 2026-06-26 · disclosed as MAL-2026-6498 on 2026-06-26

Why PkgRadar flagged 1.0.4

SeveritySignalEvidence
highInstall Lifecycle Dns Or Oast
mediumNew Account With Lifecycle Hook

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.4High risk352026-06-26
1.0.5High risk352026-06-26
1.0.3High risk352026-06-26
1.0.2High risk352026-06-26
1.0.1High risk352026-06-26
1.0.0High risk52026-06-26

Related campaigns

Block this in CI

PkgRadar gates dttfdsdee (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]