PkgRadar

npm · registry.npmjs.org

nativescript

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 9.1.0-dev.2026-06-16-27624885927

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/lib/services/doctor-service.js
mediumRemote Payloadmatched "curl " · package/setup/mac-startup-shell-script.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
9.1.0-dev.2026-06-16-27624885927Review182026-06-16
9.0.7-next.2026-06-15-27575981669Review182026-06-15
9.1.0-alpha.10Review182026-06-15
9.0.7-next.2026-06-15-27562979720Review182026-06-15
9.0.7-next.2026-06-15-27561691740Review182026-06-15
9.0.7-next.2026-06-15-27560035328Review182026-06-15
9.0.7-next.2026-06-15-27560714351Review182026-06-15
9.0.7-next.2026-06-15-27559905062Review182026-06-15
9.0.7-next.2026-06-15-27559856305Review182026-06-15
9.1.0-dev.2026-06-14-27492390552Review182026-06-14
9.1.0-dev.2026-06-14-27491330097Review182026-06-14
9.1.0-dev.2026-06-14-27489723395Review182026-06-14
9.1.0-dev.2026-06-13-27452878241Review182026-06-13
9.1.0-alpha.9Review182026-06-12
9.1.0-alpha.8Review182026-06-12
9.0.7-next.2026-06-12-27439650831Review182026-06-12
9.0.6Review182026-06-10
9.0.7-next.2026-06-10-27250151000Review182026-06-10
9.1.0-dev.2026-06-10-27292332435Review182026-06-10
9.1.0-alpha.7Review182026-06-10
9.1.0-dev.2026-06-04-26923378887Review182026-06-04
9.1.0-dev.2026-06-01-26739546406Review182026-06-01
9.1.0-alpha.4Review182026-05-29
9.1.0-alpha.5Review182026-05-29
9.0.7-next.2026-05-29-26662776952Review182026-05-29
9.1.0-alpha.3Review182026-05-29
9.1.0-next.2026-05-28-26609332083Review272026-05-29
9.1.0-dev.2026-05-29-26613502001Review272026-05-29
9.0.7-next.2026-05-22-26267331378Review232026-05-27
9.1.0-alpha.2Review232026-05-27

Block this in CI

PkgRadar gates nativescript (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]