PkgRadar

npm · registry.npmjs.org

spudmobile-bridge

Install Lifecycle Remote Or Exec: postinstall="node -e \"const p=require('path'),fs=require('fs');const d=p.join(__dirname,'node_modules','node-pty','prebuilds');['darwin-arm64','darwin-x64'].forEach(a=>{const f=p.join(d,a,'spawn-helper');try{fs.chmodSync(f,0o755)}catch{}})\""

Why PkgRadar flagged 2.4.49

SeveritySignalEvidence
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const p=require('path'),fs=require('fs');const d=p.join(__dirname,'node_modules','node-pty','prebuilds');['darwin-arm64','darwin-x64'].forEach(a=>{const f=p.join(d,a,'spawn-helper');try{fs.chmodSync(f,0o755)}catch{}})\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.4.49High risk352026-06-10
2.4.48High risk242026-06-10
2.4.47High risk242026-06-10
2.4.46High risk352026-06-10
2.4.45High risk352026-06-10
2.4.44High risk352026-06-10
2.4.43High risk352026-06-10
2.4.42High risk352026-06-10
2.4.41High risk352026-06-10
2.4.40High risk352026-06-10
2.4.39High risk242026-06-10
2.4.38High risk352026-06-10
2.4.37Review52026-05-29
2.4.35Review32026-05-27
2.4.36Review32026-05-27
2.4.16Review52026-05-26
2.4.17Review52026-05-26
2.3.9Review32026-05-26
2.4.0Review32026-05-26
2.3.7Review52026-05-26
2.3.6Review52026-05-25
2.3.5Review52026-05-25
2.3.4Review52026-05-25
2.3.3Review52026-05-25

Block this in CI

PkgRadar gates spudmobile-bridge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]