PkgRadar

npm · registry.npmjs.org

poe-code

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 3.0.372

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/providers/claude-code.js
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/providers/goose.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.372Review152026-06-16
3.0.371Review152026-06-16
3.0.370Review152026-06-16
3.0.369Review152026-06-16
3.0.368Review152026-06-16
3.0.367Review152026-06-16
3.0.366Review152026-06-16
3.0.365Review152026-06-16
3.0.364Review152026-06-16
3.0.363Review152026-06-16
3.0.362Review152026-06-16
3.0.361Review152026-06-16
3.0.360Review152026-06-16
3.0.359Review152026-06-16
3.0.358Review152026-06-16
3.0.357Review152026-06-16
3.0.356Review152026-06-16
3.0.355Review152026-06-16
3.0.354Review152026-06-16
3.0.353Review152026-06-16
3.0.352Review152026-06-16
3.0.351Review152026-06-16
3.0.350Review152026-06-16
3.0.349Review152026-06-16
3.0.348Review152026-06-16
3.0.347Review152026-06-16
3.0.346Review152026-06-16
3.0.345Review152026-06-16
3.0.344Review152026-06-16
3.0.342Review152026-06-16
3.0.343Review152026-06-16
3.0.341Review152026-06-16
3.0.340Review152026-06-16
3.0.339Review152026-06-16
3.0.338Review152026-06-16
3.0.337Review152026-06-16
3.0.336Review152026-06-16
3.0.335Review152026-06-16
3.0.334Review152026-06-16
3.0.333Review152026-06-16
3.0.332Review152026-06-16
3.0.331Review152026-06-16
3.0.330Review152026-06-16
3.0.329Review152026-06-16
3.0.328Review152026-06-16
3.0.327Review152026-06-16
3.0.326Review152026-06-16
3.0.325Review152026-06-16
3.0.324Review152026-06-16
3.0.323Review152026-06-16
3.0.321Review152026-06-16
3.0.322Review152026-06-16
3.0.320Review152026-06-16
3.0.319Review152026-06-16
3.0.318Review152026-06-16
3.0.317Review152026-06-16
3.0.316Review152026-06-16
3.0.315Review152026-06-16
3.0.314Review152026-06-16
3.0.312Review152026-06-16
3.0.313Review152026-06-16
3.0.311Review152026-06-16
3.0.310Review152026-06-16
3.0.309Review152026-06-16
3.0.308Review152026-06-16
3.0.307Review152026-06-16
3.0.306Review152026-06-16
3.0.305Review152026-06-15
3.0.304Review152026-06-15
3.0.303Review152026-06-15
3.0.302Review152026-06-15
3.0.301Review152026-06-15
3.0.300Review152026-06-15
3.0.299Review152026-06-15
3.0.298Review152026-06-15
3.0.297Review152026-06-15
3.0.296Review152026-06-15
3.0.295Review152026-06-15
3.0.294Review152026-06-15
3.0.293Review152026-06-15
3.0.291Review152026-06-15
3.0.292Review152026-06-15
3.0.290Review152026-06-15
3.0.289Review152026-06-15
3.0.288Review152026-06-15
3.0.287Review152026-06-15
3.0.286Review152026-06-15
3.0.285Review152026-06-15
3.0.284Review152026-06-15
3.0.283Review152026-06-15
3.0.282Review152026-06-15
3.0.281Review152026-06-15
3.0.280Review152026-06-15
3.0.279Review152026-06-15
3.0.278Review152026-06-15
3.0.277Review152026-06-15
3.0.276Review152026-06-15
3.0.275Review152026-06-15
3.0.274Review152026-06-15
3.0.273Review152026-06-15
3.0.272Review152026-06-15
3.0.271Review152026-06-15
3.0.270Review152026-06-15
3.0.269Review152026-06-15
3.0.268Review152026-06-15
3.0.267Review152026-06-15
3.0.266Review152026-06-15
3.0.265Review152026-06-15
3.0.264Review152026-06-14
3.0.263Review152026-06-14
3.0.262Review152026-06-14
3.0.261Review152026-06-14
3.0.260Review152026-06-14
3.0.259-beta.1Review152026-06-14
3.0.259Review152026-06-14
3.0.258Review152026-06-14
3.0.257Review152026-06-12
3.0.257-beta.1Review152026-06-12
3.0.256Review152026-06-12
3.0.256-beta.1Review152026-06-12
3.0.255Review152026-06-12
3.0.254Review152026-06-11
3.0.254-beta.1Review152026-06-11
3.0.253Review152026-06-11
3.0.252Review152026-06-11
3.0.250Review152026-06-10
3.0.249Review152026-06-09
3.0.248Review152026-06-09
3.0.247Review152026-06-09
3.0.246Review152026-06-09
3.0.245Review152026-06-09
3.0.244Review152026-06-09
3.0.243Review152026-06-09
3.0.242Review152026-06-09
3.0.241Review162026-06-08
3.0.240Review162026-06-08
3.0.239Review162026-06-07
3.0.238Review162026-06-07
3.0.237Review162026-06-07
3.0.236Review162026-06-07
3.0.235Review162026-06-07
3.0.234Review162026-06-07
3.0.232Review162026-06-04
3.0.233Review162026-06-04
3.0.231Review162026-06-03
3.0.230Review162026-06-02
3.0.229Review162026-06-02
3.0.228Review122026-05-27
3.0.226Review122026-05-27
3.0.227Review122026-05-27

Block this in CI

PkgRadar gates poe-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]