PkgRadar

npm · registry.npmjs.org

gen-api-types

Install-time lifecycle script: preinstall="echo preinstall 。。。"

Why PkgRadar flagged 1.0.5

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspreinstall added in 1.0.5 vs 1.0.4: "echo preinstall 。。。" · package.json
highNew Lifecycle Script Vs Previouspostinstall added in 1.0.5 vs 1.0.4: "echo postinstall 。。。" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.12Review72026-06-16
1.0.11Review102026-06-16
1.0.10Review102026-06-16
1.0.9Review102026-06-16
1.0.3Low risk02026-06-16
1.0.4Low risk02026-06-16
1.0.5High risk902026-06-16
1.0.8Review102026-06-16

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates gen-api-types (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]