PkgRadar

npm · registry.npmjs.org

yiyan-browser-agent

Install-time lifecycle script: postinstall="node src/postinstall.js"

Why PkgRadar flagged 1.0.32

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 1.0.32 vs 1.0.31: "node src/postinstall.js" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.32High risk452026-06-10
1.10.2Review52026-06-02
1.10.1Review52026-06-02
1.10.0Review52026-06-02
1.9.0Review52026-06-02
1.8.5Review52026-06-01
1.8.4Review32026-06-01
1.7.0Review32026-06-01
1.6.9Review52026-06-01
1.6.1Review32026-06-01
1.6.0Review52026-06-01
1.5.2Review32026-06-01
1.5.3Review32026-06-01
1.5.1Review32026-06-01
1.5.0Review32026-06-01
1.4.11Review32026-06-01
1.4.10Review32026-06-01
1.4.9Review32026-06-01
1.4.8Review32026-06-01
1.4.7Review32026-06-01
1.0.33Review32026-06-01
1.0.31Low risk02026-06-01
1.0.30Review32026-06-01
1.0.29Review32026-06-01
1.0.28Review32026-05-30
1.0.27Review32026-05-30
1.0.26Review52026-05-30
1.0.25Review52026-05-30
1.0.24Review32026-05-30
1.0.23Review52026-05-30
1.0.22Review52026-05-30
1.0.4Review52026-05-30
1.0.3Review52026-05-30
1.4.5Review32026-05-30
1.4.6Review32026-05-30
1.0.1Review242026-05-28
1.0.0Review242026-05-28

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates yiyan-browser-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]