PkgRadar

npm · registry.npmjs.org

sharp

Native Addon Gyp Action: binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)

Why PkgRadar flagged 0.35.2-rc.0

SeveritySignalEvidence
highNative Addon Gyp Actionbinding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle) · package/src/binding.gyp

Scanned versions

VersionVerdictScoreScanned (UTC)
0.35.2-rc.0High risk102026-06-16
0.33.5High risk122026-06-16
0.34.5High risk122026-06-15
0.35.1High risk102026-06-11
0.35.1-rc.1High risk102026-06-11
0.35.1-rc.0High risk102026-06-11
0.35.0High risk102026-06-10
0.35.0-rc.8High risk102026-06-10
0.35.0-rc.6Low risk02026-06-07
0.35.0-rc.5Low risk02026-06-07
0.35.0-rc.4Low risk02026-06-07

Campaign attribution

Part of the Miasma worm campaign.

Block this in CI

PkgRadar gates sharp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]