PkgRadar

Package evidence

@muyichengshayu/[email protected]

Large Javascript Payload: 2055683 bytes

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
199
Versions published
67
First published
Mar 2026
Publisher
muyichengshayu

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@muyichengshayu/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@muyichengshayu/[email protected]"],"fail_on":"review"}'
Artifact bytes7,216,921
Previous version0.2.17
Published2026-05-28T13:01:04.567Z
SHA-2562356ec13df1537b896ee386b7a04578131950e5c6334225801a33d8b8ed81865

Why flagged

What the scanner saw

Large Javascript Payload: 2055683 bytes

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
10Score
0.2.18Version
Status history (1 event)
  1. newavailable · risk review · score 10 · status changed

Evidence

Static findings

1 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/apps/web/dist/assets/vendor-shiki-core-1BqeTDsZ.js2055683 bytes10

Manifest

Package metadata

Scripts29
  • buildpnpm -r build
  • chaos:runner-killnode scripts/chaos-runner-kill.mjs
  • devnode scripts/dev.mjs
  • dev:tailscalenode scripts/dev-tailscale.mjs
  • dev:tailscale:autonode scripts/dev-tailscale.mjs --auto
  • doctornode scripts/doctor.mjs
  • e2e:real-agentsnode scripts/e2e-real-agent-runs.mjs
  • e2e:real-stopnode scripts/e2e-real-agent-stop.mjs
  • lintpnpm -r lint
  • load:control-planenode scripts/load-control-plane.mjs
  • load:sse-fanoutnode scripts/load-sse-fanout.mjs
  • load:stop-stormnode scripts/load-stop-storm.mjs
  • local:runner-checknode scripts/local-runner-check.mjs --profile quick
  • local:runner-check:nightlynode scripts/local-runner-check.mjs --profile nightly
  • local:runner-check:task:installnode scripts/local-runner-check-task.mjs install
  • local:runner-check:task:removenode scripts/local-runner-check-task.mjs remove
  • pack:drynpm pack --dry-run
  • perf:runner-splitnode scripts/perf-runner-split.mjs
  • relay:startnode scripts/relay.mjs
  • releasenode scripts/release.mjs publish
  • release:checknode scripts/release.mjs check
  • release:check:importsnode scripts/check-package-runtime-imports.mjs
  • restartpnpm stop && pnpm build && node scripts/service.mjs start
  • smoke:realtimenode scripts/smoke-realtime-sync.mjs
  • smoke:runner-splitnode scripts/smoke-runner-split.mjs
  • soak:runner-splitnode scripts/soak-runner-split.mjs
  • startpnpm build && node scripts/service.mjs start
  • statusnode scripts/service.mjs status
  • stopnode scripts/service.mjs stop
Dependencies11
  • @fastify/cors11.2.0
  • @fastify/multipart9.4.0
  • @fastify/static9.0.0
  • @napi-rs/canvas0.1.96
  • better-sqlite312.8.0
  • fastify5.8.2
  • iconv-lite0.7.2
  • nanoid5.1.6
  • pdfjs-dist5.5.207
  • sql.js1.13.0
  • ws8.18.3