PkgRadar

Package evidence

@doubao-apps/[email protected]

Native Binary Main Entry: main/bin entry points to a compiled binary: bin entry

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
977
Versions published
29
First published
Mar 2026
Publisher
wangyiming.777

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@doubao-apps/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@doubao-apps/[email protected]"],"fail_on":"high"}'
Artifact bytes27,165,064
Previous version0.0.33
Published2026-06-11T03:55:38.340Z
SHA-256d08f0d57d53e766b664d7c0fd0ae0b288e8c6cee5e334d19a10d812b1f94eb98

Why flagged

What the scanner saw

Native Binary Main Entry: main/bin entry points to a compiled binary: bin entry

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
50Score
0.0.34-canary-d294d04f-20260611035121Version
Status history (1 event)
  1. newavailable · risk high · score 50 · status changed

Evidence

Static findings

4 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highNative Binary Main Entrypackage.jsonmain/bin entry points to a compiled binary: bin entry45
Show all 4 findings (low-signal and informational)
SeverityKindPathDetailPoints
highNative Binary Main Entrypackage.jsonmain/bin entry points to a compiled binary: bin entry45
lowCredential file accesspackage/dist/805.jsmatched ".npmrc"5
lowLarge Javascript Payloadpackage/dist/751.js15148318 bytes0
lowLarge Javascript Payloadpackage/dist/0~@byted-hdt/cli.js4499740 bytes0

Manifest

Package metadata

Scripts4
  • buildrimraf dist && rslib build
  • devrslib build --watch
  • testvitest run --coverage
  • test:uvitest run --coverage -u
Dependencies30
  • @lynx-js/external-bundle-rsbuild-pluginnpm:@lynx-js/external-bundle-rsbuild-plugin-canary@0.1.1-canary-20260415-e5b0f668
  • @lynx-js/react-alias-rsbuild-plugin0.12.7
  • @lynx-js/react-rsbuild-pluginnpm:@lynx-js/[email protected]
  • @lynx-js/rspeedy0.13.3
  • @lynx-js/runtime-wrapper-webpack-plugin0.1.3
  • @manypkg/get-packages2.2.0
  • @pnpm/lockfile.fs1001.1.18
  • @rsbuild/core1.7.2
  • @rsbuild/plugin-less1.2.4
  • @rsbuild/plugin-sass1.5.0
  • @rsbuild/plugin-type-check1.2.1
  • @swc/core1.15.11
  • ansi-escapes7.2.0
  • archiver7.0.1
  • chalk5.6.2
  • commander12.0.0
  • execa5.0.1
  • express5.2.1
  • inquirer13.1.0
  • inquirer-search-list^1.2.6
  • jiti^2.4.2
  • lodash-es4.17.21
  • magic-string^0.30.0
  • npm-packlist10.0.1
  • ora^5.0.0
  • package-manager-detector1.3.0
  • picocolors1.1.1
  • playwright-core^1.56.1
  • swc-walk1.0.1
  • tapable2.2.1
Optional dependencies1
  • @napi-rs/keyring^1.2.0