Postinstall fetches an opaque executable and, on Windows, a native addon; the CLI launcher later executes the fetched binary. The package source does not authenticate these payloads.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
apex.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L52Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L52Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
apex.cjsView on unpkg