PkgRadar

npm · registry.npmjs.org

makecoder

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 4.0.72

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 4.0.72 vs 4.0.71: "node scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.1.22Review32026-06-16
4.1.21Review32026-06-16
4.1.20Review32026-06-16
4.1.19Review32026-06-16
4.1.18Review32026-06-16
4.1.17Review32026-06-15
4.1.15Review32026-06-15
4.0.72High risk752026-06-10
4.0.76Review172026-06-04
4.0.73Review242026-06-01
4.0.71Review212026-06-01
4.0.70Review212026-06-01
4.0.69Review212026-06-01
4.0.68Review302026-06-01
4.0.66Review212026-06-01
4.0.67Review212026-06-01
4.0.57Review242026-05-30
4.0.56Review242026-05-30
4.0.51Review242026-05-30
4.0.49Review242026-05-30
4.0.53Review242026-05-30
4.0.50Review242026-05-30
4.0.45Review242026-05-30
4.0.65Review1522026-05-28
4.0.63Review1422026-05-27
4.0.59Review1422026-05-27
4.0.60Review1422026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates makecoder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]