PkgRadar

npm · registry.npmjs.org

oh-my-harness-loop

Install-time lifecycle script: postinstall="node ./scripts/postinstall.js"

Why PkgRadar flagged 2026.6.303

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2026.6.303 vs 2026.6.302: "node ./scripts/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.303High risk452026-06-10
2026.6.313Review52026-06-03
2026.6.312Review52026-06-03
2026.6.306Review52026-06-03
2026.6.305Review52026-06-03
2026.6.304Review52026-06-03
2026.6.302Low risk02026-06-03
2026.6.301Low risk02026-06-03

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates oh-my-harness-loop (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]