PkgRadar

npm · registry.npmjs.org

nx

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('./dist/bin/post-install')}catch(e){}\""

Why PkgRadar flagged 22.7.0-pr.33655.2b96277

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 22.7.0-pr.33655.2b96277 vs 22.7.0-pr.33655.12b0dd7: "node -e \"try{require('./dist/bin/post-install')}catch(e){}\"" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('./dist/bin/post-install')}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
23.0.0-canary.20260612-10af44fReview162026-06-12
23.0.0-rc.3Review162026-06-12
23.0.0-rc.2Review162026-06-12
23.0.0-canary.20260612-d5143c0Review162026-06-12
23.0.0-rc.1Review162026-06-12
23.0.0-rc.0Review162026-06-11
23.0.0-canary.20260610-ab099bdReview162026-06-10
22.7.0-pr.33655.2b96277High risk802026-06-10
22.7.0-pr.33655.d8f5d50Review12026-06-10
22.7.0-beta.9Review122026-06-10
23.0.0-beta.25Review162026-06-09
23.0.0-canary.20260609-b9a0582Review162026-06-09
23.0.0-beta.24Review132026-06-06
23.0.0-beta.23Review132026-06-04
23.0.0-canary.20260603-fc8444bReview132026-06-03
23.0.0-beta.22Review132026-06-03
23.0.0-canary.20260602-6ca3f3aReview132026-06-02
23.0.0-beta.21Review132026-06-01
23.0.0-beta.20Review92026-05-28
22.7.5Review92026-05-28
23.0.0-beta.19Review92026-05-25
22.7.4Review92026-05-25

Block this in CI

PkgRadar gates nx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]