PkgRadar

Package evidence

@happy-creative/[email protected]

Js Remote Exe Exec, Js Hidden Powershell, Tls Verification Disabled +3 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
8
First published
Jul 2026
Publisher
neyio

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@happy-creative/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@happy-creative/[email protected]"],"fail_on":"high"}'
Publisherneyio
Artifact bytes23,598,544
Previous version0.0.9
Published2026-07-21T12:06:42.308Z
SHA-256de08aa242b419a08566f682e6ac7bb03ea3b1b89497d7e544895c75e9fa4eaac

Why flagged

What the scanner saw

Js Remote Exe Exec

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
139Score
0.0.10Version
Status history (1 event)
  1. newavailable · risk high · score 139 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burstactive

Publisher burst: neyio

13 members · evidence strength 84
Publisher / release actor burstcandidate

Publisher burst: neyio

13 members · max score 262

Evidence

Static findings

18 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highJs Remote Exe Execmanifest45
highJs Hidden Powershellmanifest45
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumCredential file accessmanifest10
Show all 18 findings (low-signal and informational)
SeverityKindPathDetailPoints
highJs Remote Exe Execmanifest45
highJs Hidden Powershellmanifest45
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumCredential file accessmanifest10
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0

Manifest

Package metadata

Optional dependencies13
  • @lydell/node-pty1.2.0-beta.10
  • @lydell/node-pty-darwin-arm641.2.0-beta.10
  • @lydell/node-pty-darwin-x641.2.0-beta.10
  • @lydell/node-pty-linux-x641.2.0-beta.10
  • @lydell/node-pty-win32-arm641.2.0-beta.10
  • @lydell/node-pty-win32-x641.2.0-beta.10
  • @teddyzhu/clipboard0.0.5
  • @teddyzhu/clipboard-darwin-arm640.0.5
  • @teddyzhu/clipboard-darwin-x640.0.5
  • @teddyzhu/clipboard-linux-arm64-gnu0.0.5
  • @teddyzhu/clipboard-linux-x64-gnu0.0.5
  • @teddyzhu/clipboard-win32-arm64-msvc0.0.5
  • @teddyzhu/clipboard-win32-x64-msvc0.0.5