PkgRadar

npm · registry.npmjs.org

wyrm-mcp

Install-time lifecycle script: preinstall="node scripts/preinstall.cjs"

Why PkgRadar flagged 5.3.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 5.3.0 vs 5.2.2: "node scripts/postinstall.cjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
7.0.3Review142026-06-13
7.0.2Review142026-06-13
7.0.1Review142026-06-13
7.0.0Review142026-06-13
6.18.1Review142026-06-12
6.18.0Review142026-06-12
5.3.0High risk502026-06-10
6.17.0Review142026-06-08
6.16.0Review142026-06-07
6.15.0Review202026-06-07
6.14.1Review142026-06-06
6.12.0Review202026-06-04
6.13.0Review142026-06-04
6.11.0Review202026-06-04
6.10.0Review102026-06-04
6.9.1Review102026-06-04
6.9.0Review102026-06-04
6.8.2Review72026-06-04
6.8.1Review102026-06-04
6.8.0Review72026-06-04
6.3.1Review72026-06-02
6.2.1Review102026-06-01
6.2.0Review102026-05-30
6.1.7Review72026-05-29
6.1.5Review72026-05-27
6.1.6Review72026-05-27
6.0.1Review102026-05-26
6.0.2Review102026-05-26
5.2.2Review52026-05-26

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates wyrm-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]