PkgRadar

npm · registry.npmjs.org

icoa-cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('./dist/postinstall.js')}catch(e){}\""

Why PkgRadar flagged 2.19.288

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('./dist/postinstall.js')}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.19.288High risk172026-06-17
2.19.287High risk172026-06-15
2.19.286High risk172026-06-15
2.19.285High risk172026-06-15
2.19.284High risk172026-06-15
2.19.282High risk172026-06-15
2.19.283High risk172026-06-15
2.19.280High risk172026-06-15
2.19.281High risk172026-06-15
2.19.279High risk172026-06-15
2.19.277High risk172026-06-15
2.19.278High risk172026-06-15
2.19.276High risk172026-06-15
2.19.274High risk172026-06-14
2.19.275High risk172026-06-14
2.19.273High risk172026-06-14
2.19.271High risk172026-06-14
2.19.272High risk172026-06-14
2.19.270High risk172026-06-14
2.19.269High risk172026-06-14
2.19.268High risk172026-06-14
2.19.267High risk172026-06-13
2.19.266High risk172026-06-13
2.19.265High risk172026-06-13
2.19.264High risk172026-06-13
2.19.263High risk172026-06-13
2.19.234High risk172026-06-13
2.19.233High risk172026-06-13
2.19.232High risk352026-06-13
2.19.231High risk172026-06-13
2.19.261High risk242026-06-10
2.19.262High risk242026-06-10
2.19.229High risk242026-06-10
2.19.230High risk242026-06-10
2.19.222High risk242026-06-10
2.19.223High risk242026-06-10
2.19.219High risk352026-06-10
2.19.218High risk242026-06-10
2.19.216High risk352026-06-10
2.19.217High risk242026-06-10
2.19.260High risk242026-06-10
2.19.259High risk352026-06-10
2.19.257High risk242026-06-10
2.19.256High risk242026-06-10
2.19.255High risk242026-06-10
2.19.254High risk242026-06-10
2.19.253High risk352026-06-10
2.19.252High risk242026-06-10
2.19.251High risk242026-06-10
2.19.250High risk242026-06-10
2.19.248High risk242026-06-10
2.19.249High risk242026-06-10
2.19.247High risk242026-06-10
2.19.246High risk242026-06-10
2.19.245High risk242026-06-10
2.19.244High risk242026-06-10
2.19.243High risk352026-06-10
2.19.242High risk242026-06-10
2.19.241High risk242026-06-10
2.19.240High risk242026-06-10
2.19.238High risk242026-06-10
2.19.239High risk242026-06-10
2.19.236High risk242026-06-10
2.19.209High risk242026-06-10
2.19.210High risk242026-06-10
2.19.194High risk352026-06-10
2.19.208High risk242026-06-10
2.19.207High risk242026-06-10
2.19.205High risk242026-06-10
2.19.206High risk242026-06-10
2.19.204High risk242026-06-10
2.19.197High risk242026-06-10
2.19.200High risk242026-06-10
2.19.196High risk242026-06-10
2.19.195High risk242026-06-10
2.19.201High risk242026-06-10
2.19.202High risk242026-06-10
2.19.198High risk242026-06-10
2.19.199High risk242026-06-10
2.19.203High risk312026-06-10
2.19.235High risk242026-06-10

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates icoa-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]