PkgRadar

npm · registry.npmjs.org

@1agh/maude

Remote Payload: matched "curl "

Why PkgRadar flagged 0.28.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/plugins/design/dev-server/bin/prep.sh
mediumRemote Payloadmatched "curl " · package/plugins/design/dev-server/bin/runtime-health.sh
mediumRemote Payloadmatched "curl " · package/plugins/design/dev-server/bin/server-up.sh
mediumRemote Payloadmatched "curl " · package/plugins/design/dev-server/bin/svg-optimize.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.28.1High risk532026-06-10
0.29.0High risk372026-06-10
0.28.0High risk532026-06-10
0.27.0High risk372026-06-10
0.26.0High risk372026-06-10
0.25.0High risk412026-06-10
0.24.0Review412026-05-30
0.22.0Review202026-05-30
0.23.0Review392026-05-28
0.22.2Review352026-05-27
0.20.0Review272026-05-26
0.19.1Review272026-05-26
0.19.0Review272026-05-26
0.18.1Review272026-05-25
0.18.2Review272026-05-25
0.17.2Review272026-05-25
0.17.1Review272026-05-25
0.16.0Review272026-05-25

Block this in CI

PkgRadar gates @1agh/maude (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @1agh/[email protected]