PkgRadar

npm · registry.npmjs.org

remote-bridge-prod

Install Lifecycle Remote Or Exec: postinstall="node -e \"try{require('child_process').execSync('chmod +x '+require('path').dirname(require.resolve('node-pty/package.json'))+'/prebuilds/*/spawn-helper 2>/dev/null',{shell:true})}catch(e){}\""

Why PkgRadar flagged 2.0.10

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"try{require('child_process').execSync('chmod +x '+require('path').dirname(require.resolve('node-pty/package.json'))+'/prebuilds/*/spawn-helper 2>/dev/null',{shell:true})}catch(e){}\"" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="node -e \"try{require('child_process').execSync('chmod +x '+require('path').dirname(require.resolve('node-pty/package.json'))+'/prebuilds/*/spawn-helper 2>/dev/null',{shell:true})}catch(e){}\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.10High risk552026-06-11
2.0.9High risk552026-06-11
2.0.8High risk552026-06-11
2.0.7High risk552026-06-11
2.0.6High risk552026-06-11
2.0.5High risk552026-06-10
2.0.4High risk552026-06-10
2.0.3High risk552026-06-10
2.0.2High risk252026-06-10
2.0.1High risk652026-06-10
2.0.0Low risk02026-06-10

Related campaigns

Block this in CI

PkgRadar gates remote-bridge-prod (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]