npm · registry.npmjs.org
hbsig
Install Lifecycle Binary Exec: preinstall="./bin/install-deps"
Early detection
PkgRadar flagged this 1.6 days before public disclosure
Detected 2026-06-03 · disclosed as MAL-2026-5190 on 2026-06-04
Why PkgRadar flagged 0.3.2
| Severity | Signal | Evidence |
|---|---|---|
| high | New Lifecycle Script Vs Previous | preinstall added in 0.3.2 vs 0.3.1: "./bin/install-deps" · package.json |
| medium | Install Lifecycle Binary Exec | preinstall="./bin/install-deps" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.3.2 | High risk | 60 | 2026-06-10 |
0.3.3 | Low risk | 0 | 2026-05-27 |
0.3.0 | Low risk | 0 | 2026-05-25 |
0.3.1 | Low risk | 0 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]