PkgRadar

npm · registry.npmjs.org

its-over-9k

Install Lifecycle Remote Or Exec: postinstall="node scripts/use-prebuild.cjs && node -e \"try{require('child_process').execSync('node dist/cli.js update-skills',{stdio:'ignore'})}catch(e){}\""

Why PkgRadar flagged 1.3.7

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node scripts/use-prebuild.cjs && node -e \"try{require('child_process').execSync('node dist/cli.js update-skills',{stdio:'ignore'})}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.7High risk352026-06-10
1.3.8High risk352026-06-10

Related campaigns

Block this in CI

PkgRadar gates its-over-9k (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]