Package evidence
[email protected]
Remote Dependency Spec: dependencies.cross-spawn="https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz"
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Weekly downloads
- 196
- Versions published
- 18Established · −30% score
- First published
- May 2023
- Publisher
- dimaslanjaka
Effective trust discount applied: −30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.
Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Remote Dependency Spec: dependencies.cross-spawn="https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz"
1 candidate cluster(s) currently reference this release. 3 remote tarball(s) were followed statically.
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (2 events)
- available → available · risk high · score 72 · status available -> available, risk high -> high, score 136 -> 72
- new → available · risk high · score 136 · status changed
Related candidates
Linked campaigns and clusters
dimaslanjaka
3 members · evidence strength 65dimaslanjaka
3 members · max score 72Evidence
Static findings
3 static · 3 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Remote Dependency Spec | package.json | dependencies.cross-spawn="https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz" | 12 |
| high | Remote Dependency Spec | package.json | dependencies.git-command-helper="https://github.com/dimaslanjaka/git-command-helper/raw/ed17f70eb7444d24bd8eb984a4afe9fd64652838/release/git-command-helper.tgz" | 12 |
| high | Remote Dependency Spec | package.json | dependencies.sbg-utility="https://github.com/dimaslanjaka/static-blog-generator/raw/44e5c7b79b4e60f8c2d34857c27b8ce677d7493e/packages/sbg-utility/release/sbg-utility.tgz" | 12 |
| high | New Remote Dependency Vs Previous | package.json | dependencies.cross-spawn added in 2.0.13 vs 2.0.12: "https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz" | 12 |
| high | New Remote Dependency Vs Previous | package.json | dependencies.git-command-helper added in 2.0.13 vs 2.0.12: "https://github.com/dimaslanjaka/git-command-helper/raw/ed17f70eb7444d24bd8eb984a4afe9fd64652838/release/git-command-helper.tgz" | 12 |
| high | New Remote Dependency Vs Previous | package.json | dependencies.sbg-utility added in 2.0.13 vs 2.0.12: "https://github.com/dimaslanjaka/static-blog-generator/raw/44e5c7b79b4e60f8c2d34857c27b8ce677d7493e/packages/sbg-utility/release/sbg-utility.tgz" | 12 |
Remote payloads
Followed remote artifacts
| Source | URL | Risk | Score | Summary |
|---|---|---|---|---|
| dependencies.cross-spawn | https://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgz | error | 0 | unexpected end of file |
| dependencies.git-command-helper | https://github.com/dimaslanjaka/git-command-helper/raw/ed17f70eb7444d24bd8eb984a4afe9fd64652838/release/git-command-helper.tgz | error | 0 | unexpected end of file |
| dependencies.sbg-utility | https://github.com/dimaslanjaka/static-blog-generator/raw/44e5c7b79b4e60f8c2d34857c27b8ce677d7493e/packages/sbg-utility/release/sbg-utility.tgz | error | 0 | unexpected end of file |
Manifest
Package metadata
Scripts16
buildtsc -b tsconfig.build.json && npm run build-tsup && npm run build-exportsbuild-exportsnode -r ts-node/register -r dotenv/config build.mjsbuild-packagesyarn workspaces foreach --worktree --exclude=binary-collections --no-private run buildbuild-rolluprollup -c rollup.config.jsbuild-tsupnode build.tsup.jscleanrimraf lib tmp/dist binariespacknode package.cjs --yarn --filename=binpreparehuskypuppeteer:browsernpx -y puppeteer browsers install chrometesttest-cjstest-coveragenpm test --coverage --detectOpenHandlestest-esmtest-esmtest-nrsnpm test -- nrs build-**test-watchnpm test --watchupdate:ncunpx npm-check-updates -u --enginesNode --root -x jest -x @types/jest -x babel-jest -x @babel/core -x @babel/preset-env -x @babel/preset-typescript -x ts-jest -x eslint -x @eslint/eslintrc -x @eslint/js -x @typescript-eslint/eslint-plugin -x @typescript-eslint/parser -x eslint-config-prettier -x eslint-plugin-prettier -x typescript-eslint -x prettier -x typescript -x ts-node -x @yarnpkg/coreupdate:packercurl -L https://github.com/dimaslanjaka/nodejs-package-types/raw/main/packer.js > packer.cjs
Dependencies22
@yarnpkg/core^4.7.0ansi-colors^4.1.3axios^1.16.1cross-spawnhttps://github.com/dimaslanjaka/node-cross-spawn/raw/78b09a1f799430fb251c1b438ec56ce7957674f4/release/cross-spawn.tgzcrypto-js^4.2.0dotenv^17.4.2fs-extra^11.3.5git-command-helperhttps://github.com/dimaslanjaka/git-command-helper/raw/ed17f70eb7444d24bd8eb984a4afe9fd64652838/release/git-command-helper.tgzglob^13.0.6minimatch^10.2.5minimist^1.2.8ps-node^0.1.6puppeteer^25.0.4puppeteer-extra^3.3.6puppeteer-extra-plugin-stealth^2.11.2sbg-utilityhttps://github.com/dimaslanjaka/static-blog-generator/raw/44e5c7b79b4e60f8c2d34857c27b8ce677d7493e/packages/sbg-utility/release/sbg-utility.tgztar-stream^3.2.0upath^3.0.7which^7.0.0yaml^2.9.0yarn^1.22.22zlib^1.0.5