PkgRadar

Go modules · proxy.golang.org

github.com/malbeclabs/doublezero

Remote Payload: matched "cUrl "

Why PkgRadar flagged v0.8.1-0.20260604230645-983499b2cf1e

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · github.com/malbeclabs/[email protected]/api/internal/rpc.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/client/doublezerod/cmd/doublezerod/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/config/constants.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/config/env.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/config/solana.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/controlplane/device-health-oracle/cmd/device-health-oracle/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/controlplane/funder/cmd/funder/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/controlplane/monitor/cmd/monitor/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/controlplane/telemetry/cmd/geoprobe-agent/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/controlplane/telemetry/cmd/telemetry/main.go
mediumRemote Payloadmatched "CURL " · github.com/malbeclabs/[email protected]/tools/stress/device-orchestrator/cmd/device-orchestrator/main.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.8.1-0.20260604230645-983499b2cf1eHigh risk1002026-06-06
v0.0.0-20260604230645-983499b2cf1eHigh risk1002026-06-06

Block this in CI

PkgRadar gates github.com/malbeclabs/doublezero (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/malbeclabs/[email protected]