PkgRadar

npm · registry.npmjs.org

universal-ast-mapper

Install-time lifecycle script: postinstall="node scripts/install-skill.mjs"

Why PkgRadar flagged 0.5.3

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.5.3 vs 0.5.2: "node scripts/install-skill.mjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.28.0Review32026-06-11
1.27.0Review32026-06-11
1.26.0Review32026-06-11
1.25.0Review32026-06-11
1.24.0Review32026-06-11
1.23.0Review32026-06-10
0.5.3High risk452026-06-10
1.22.1Review32026-06-09
1.22.0Review32026-06-09
1.19.0Review32026-06-09
1.18.0Review52026-06-09
1.13.0Review52026-06-08
1.11.0Review52026-06-08
1.10.0Review32026-06-08
1.7.2Review32026-06-07
1.7.0Review52026-06-07
1.6.0Review32026-06-04
1.5.0Review32026-06-04
1.3.0Review52026-06-03
1.4.0Review32026-06-03
1.2.0Review32026-06-02
1.1.0Review52026-06-02
1.0.0Review52026-06-01
0.8.6Review52026-05-31
0.8.4Review52026-05-31
0.8.2Review52026-05-30
0.8.1Review52026-05-30
0.8.0Review52026-05-29
0.7.0Review52026-05-28
0.5.2Low risk02026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates universal-ast-mapper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]