PkgRadar

npm · registry.npmjs.org

@adminforth/oauth

Remote Payload: matched "curl "

Why PkgRadar flagged 1.7.7

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/.woodpecker/buildSlackNotify.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.7.7Review62026-06-17
1.7.6Review62026-06-17
1.7.5Review62026-06-17
1.7.4Review62026-06-15
1.7.3Review62026-06-11
1.7.2Review62026-06-10
1.7.1Review62026-06-05
1.6.14Review122026-05-25
1.7.0Review122026-05-25

Block this in CI

PkgRadar gates @adminforth/oauth (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @adminforth/[email protected]