PkgRadar

npm · registry.npmjs.org

nfets

Native Addon Gyp Action: binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)

Why PkgRadar flagged 0.0.119

SeveritySignalEvidence
highNative Addon Gyp Actionbinding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle) · package/binding.gyp

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.119High risk122026-06-16
0.0.118High risk122026-06-16
0.0.117High risk122026-06-15
0.0.116High risk122026-06-12
0.0.115High risk122026-06-10
0.0.114Review12026-06-09
0.0.113Review12026-06-05
0.0.112Review12026-06-05
0.0.111Review12026-06-05
0.0.109Review12026-06-03
0.0.110Review12026-06-03
0.0.108Review12026-06-03
0.0.106Review12026-06-01
0.0.107Review12026-06-01
0.0.105Review12026-06-01
0.0.104Review12026-06-01
0.0.103Review12026-05-30
0.0.101Review162026-05-25
0.0.102Review162026-05-25

Campaign attribution

Part of the Miasma worm campaign.

Block this in CI

PkgRadar gates nfets (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]