PkgRadar

npm · registry.npmjs.org

qlogicagent

Js Hidden Powershell: Hidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers.

Why PkgRadar flagged 2.13.5

SeveritySignalEvidence
highJs Hidden PowershellHidden / non-interactive PowerShell invocation in package code — `-WindowStyle Hidden`, `irm | iex`, `windowsHide: true`, or equivalent — used to download-and-run payloads on Windows installers. · package/dist/cli/runtime-dependency-catalog.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.13.5Review562026-06-13
2.13.4Low risk02026-06-13
2.13.3Low risk02026-06-12
2.13.2Low risk02026-06-12
2.13.1Low risk02026-06-12
2.12.15Low risk02026-06-12
2.12.13Low risk02026-06-12
2.12.14Low risk02026-06-12
2.12.12Review102026-06-11
2.12.11Review72026-06-11
2.12.10Review72026-06-11
2.12.9Review102026-06-11
2.12.8Review72026-06-10
2.12.7Review102026-06-10
2.12.6Review72026-06-10
2.12.5Review72026-06-10
2.12.4Review72026-06-10
2.12.3Review72026-06-10
2.12.2Review72026-06-10
2.11.14Review72026-06-10
2.11.13Review72026-06-09
2.11.12Review72026-06-09
2.11.11Review72026-06-09
2.11.10Review72026-06-09
2.11.9Review72026-06-08
2.11.8Review102026-06-08
2.11.7Review72026-06-07
2.11.6Review72026-06-06
2.11.5Review72026-06-06
2.11.4Review102026-06-05
2.11.3Review72026-06-05
2.11.2Review72026-06-04
2.11.1Review102026-06-04
2.10.49Review102026-06-03
2.10.50Review72026-06-03
2.10.48Review102026-06-03
2.10.47Review72026-06-03
2.10.46Review72026-06-03
2.10.45Review72026-06-03
2.10.44Review72026-06-03
2.10.43Review72026-06-03
2.10.42Review72026-06-02
2.10.41Review72026-06-02
2.10.39Review102026-06-02
2.10.40Review102026-06-02
2.10.37Review72026-06-02
2.10.36Review72026-06-02
2.10.34Review72026-06-01
2.10.35Review72026-06-01
2.10.32Review72026-06-01
2.10.33Review72026-06-01
2.10.29Review102026-06-01
2.10.30Review102026-06-01
2.10.27Review102026-06-01
2.10.25Review102026-06-01
2.10.26Review72026-06-01
2.10.24Review102026-06-01
2.10.23Review72026-06-01
2.10.22Review72026-05-31
2.10.20Review72026-05-31
2.10.21Review72026-05-31
2.10.19Review72026-05-30
2.10.17Review72026-05-30
2.10.18Review72026-05-30
2.10.16Review72026-05-30
2.10.15Review102026-05-30
2.10.14Review102026-05-30
2.10.13Review102026-05-30
2.10.12Review102026-05-30
2.10.11Review102026-05-30
2.10.10Review102026-05-30
2.10.9Review102026-05-30
2.10.8Review102026-05-29
2.10.6Review102026-05-29
2.10.7Review102026-05-29
2.10.4Review102026-05-29
2.10.5Review102026-05-29
2.10.3Review102026-05-29
2.10.2Review102026-05-29
2.10.1Review102026-05-29
2.10.0Review72026-05-29
2.9.0Review72026-05-29
2.6.1Low risk02026-05-25
2.7.0Review102026-05-25

Block this in CI

PkgRadar gates qlogicagent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]