PkgRadar

npm · registry.npmjs.org

twokey

Install-time lifecycle script: postinstall="node ./bin/postinstall.js"

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.11High risk52026-06-03
1.0.10High risk52026-06-03
1.0.8High risk52026-06-03
1.0.14Review52026-05-30
1.0.24Review52026-05-30
1.0.23Review52026-05-30
1.0.22Review52026-05-30
1.0.21Review52026-05-30
1.0.20Review52026-05-30
1.0.19Review52026-05-30
1.0.16Review52026-05-30
1.0.18Review52026-05-30
1.0.17Review52026-05-30
1.0.15Review52026-05-30
1.0.13Review52026-05-30
1.0.12Review52026-05-30
1.0.9Review32026-05-30
1.0.2Low risk02026-05-24
1.0.3Low risk02026-05-24

Related campaigns

Block this in CI

PkgRadar gates twokey (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
twokey — npm malware advisory | PkgRadar