PkgRadar

npm · registry.npmjs.org

north-cli

Install Lifecycle Remote Or Exec: postinstall="node -e \"process.stdout.write('north-cli instalado. Rode: north install\\n')\""

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"process.stdout.write('north-cli instalado. Rode: north install\\n')\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.0Review102026-06-10
0.2.0High risk352026-06-10
0.1.2High risk352026-06-10
0.1.1High risk352026-06-10
0.1.0High risk352026-06-10
0.11.1Review102026-06-09
0.11.0Review102026-06-09
0.10.0Review102026-06-09
0.9.1Review102026-06-09
0.9.0Review102026-06-08
0.8.0Review102026-06-08
0.5.0Review102026-06-08
0.7.0Review102026-06-03
0.6.0Review102026-06-03
0.3.0Review102026-06-03
0.2.1Review102026-06-03

Campaign attribution

Part of the Clob dropper campaign.

Block this in CI

PkgRadar gates north-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]