PkgRadar

Package evidence

[email protected]

Js Remote Npm Install, New Account With Lifecycle Hook, Credential file access +4 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
3
First published
Jun 2026
Publisher
gl1112222

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publishergl1112222
Artifact bytes22,865,406
Previous version2.8.4
Published2026-06-26T13:30:43.415Z
SHA-2568907e26848aa6b77d780f0442109ec1e2f6a0b94670950ff565bd486714ec493

Why flagged

What the scanner saw

Js Remote Npm Install

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
110Score
2.8.5Version
Status history (1 event)
  1. newavailable · risk high · score 110 · status changed

Evidence

Static findings

18 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highJs Remote Npm Installmanifest45
highNew Account With Lifecycle Hookmanifest25
mediumSuspicious Publish Contextmanifest10
Show all 18 findings (low-signal and informational)
SeverityKindPathDetailPoints
highJs Remote Npm Installmanifest45
highNew Account With Lifecycle Hookmanifest25
mediumSuspicious Publish Contextmanifest10
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowInstall-time lifecycle scriptmanifest5
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0

Manifest

Package metadata

Dependencies4
  • @agentclientprotocol/sdk^0.19.0
  • @claude-code-best/mcp-chrome-bridge^3.0.1
  • highlight.js^11.11.1
  • ws^8.20.0
Optional dependencies1
  • doubaoime-asr^0.1.0