Package evidence
[email protected]
New Account With Lifecycle Hook: package first published 0 day(s) ago, 1 total version(s), has lifecycle hook
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 1
- First published
- Jun 2026
- Publisher
- capillary
Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
New Account With Lifecycle Hook: package first published 0 day(s) ago, 1 total version(s), has lifecycle hook
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 5 · status changed
Evidence
Static findings
2 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | New Account With Lifecycle Hook | package.json | package first published 0 day(s) ago, 1 total version(s), has lifecycle hook | 25 |
Show all 2 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | New Account With Lifecycle Hook | package.json | package first published 0 day(s) ago, 1 total version(s), has lifecycle hook | 25 |
| low | Install-time lifecycle script | package.json | preinstall="npm run npmcheckversion" | 5 |
Manifest
Package metadata
Scripts38
analyzenode ./internals/scripts/analyze.jsanalyze:cleanrimraf stats.jsonbuildcross-env NODE_OPTIONS=--max_old_space_size=4096 NODE_ENV=production webpack --config internals/webpack/webpack.prod.babel.js --color --progressbuild:analyzecross-env NODE_OPTIONS=--max_old_space_size=4096 NODE_ENV=production ANALYZE=true webpack --config internals/webpack/webpack.prod.babel.js --color --progressbuild:cleanrimraf ./distbuild:copy-all-filesbabel-node ./scripts/copy-all-files.jsbuild:librarynpm run build:copy-all-filescleanshjs ./internals/scripts/clean.jsclean:allnpm run analyze:clean && npm run test:clean && npm run build:cleanextract-intlnode ./internals/scripts/extract-intl.jsgenerateplop --plopfile internals/generators/index.jslighthousenode ./internals/lighthouselintnpm run lint:jslint:cssstylelint './app/**/*.js'lint:eslinteslint --fixlint:eslint:fixeslint --fixlint:jsnpm run lint:eslint -- applint:stagedlint-stagednpmcheckversionnode ./internals/scripts/npmcheckversion.jspostbuildnpm run extract-intl && cp app/translations/en.json distpreanalyzenpm run analyze:cleanprebuildnpm run build:cleanpreinstallnpm run npmcheckversionpreparehusky installpresetupnpm i chalk shelljsprettifyprettier --writesetupnode ./internals/scripts/setup.jssizesize-limitsonarnode ./internals/sonarstartcross-env NODE_ENV=development NODE_OPTIONS=--max_old_space_size=4000 node server- …and 8 more.
Dependencies71
@babel/polyfill7.0.0@bugsnag/js^7.2.1@bugsnag/plugin-react^7.2.1@capillarytech/cap-coupons10.0.44@capillarytech/cap-giftcards-ui2.0.19@capillarytech/cap-promo-ui1.0.25@capillarytech/cap-ui-library^8.12.64@capillarytech/cap-ui-utils^3.0.11@capillarytech/creatives-library8.0.19@capillarytech/vulcan-react-sdk^2.2.2@newrelic/browser-agent^1.293.0antd3.16.2axios^0.18.0babel-plugin-require-context-hook^1.0.0babel-plugin-transform-require-context^0.1.1chalk^2.4.2classnames^2.2.6compression1.7.3connected-react-router4.5.0cross-env5.2.0exports-loader^0.7.0express4.16.4fontfaceobserver2.0.13history4.7.2hoist-non-react-statics3.0.1husky^8.0.3immer^8.0.1immutable^4.0.0-rc.12intl1.2.5invariant2.2.4- …and 41 more.