PkgRadar

npm · registry.npmjs.org

lynkr

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 9.5.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 9.5.0 vs 9.4.6: "node scripts/check-native.js" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/routing/model-registry.js
mediumRemote Payloadmatched "curl " · package/benchmark-configs/portkey-docker.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
9.5.0High risk742026-06-11
9.4.6Review202026-06-08
9.4.5Review202026-06-08
9.4.4Review202026-06-08
9.4.3Review202026-06-08
9.4.2Review202026-06-08
9.4.1Review202026-06-08
9.4.0Review202026-06-07
9.3.3Review172026-05-30
9.3.1Review172026-05-30
9.3.2Review172026-05-30
9.2.3Review172026-05-30
9.2.2Review172026-05-30
9.2.1Review172026-05-30
9.2.0Review172026-05-30
9.1.9Review172026-05-30
9.1.8Review172026-05-30
9.1.7Review172026-05-30
9.1.6Review172026-05-30
9.1.5Review172026-05-30
9.1.4Review172026-05-29
9.1.2Review172026-05-29
9.1.3Review172026-05-29

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates lynkr (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]