PkgRadar

npm · registry.npmjs.org

@aion0/forge

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.78

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/check-forge-status.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/publish.sh
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/schedules/action-runner.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/cloudflared.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/notify.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/pipeline.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/app/api/terminal-bell/route.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/session-watcher.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/task-manager.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/telegram-bot.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/lib/telegram-standalone.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.78Review792026-06-13
0.10.77Review792026-06-13
0.10.76Review792026-06-13
0.10.75Review792026-06-12
0.10.74Review1142026-06-12
0.10.72Review792026-06-12
0.10.71Review792026-06-12
0.10.70Review792026-06-11
0.10.69Review1142026-06-11
0.10.68Review792026-06-11
0.10.67Review792026-06-10
0.10.66Review1142026-06-10
0.10.65Review1142026-06-10
0.10.64Review1142026-06-10
0.10.58Review792026-06-10
0.10.57Review1022026-06-10
0.10.56Review712026-06-10
0.10.55Review712026-06-10
0.8.8Review1052026-06-10
0.8.6Review1052026-06-10
0.8.7Review1052026-06-10
0.10.53Review1022026-06-10
0.10.51Review712026-06-09
0.10.50Review712026-06-09
0.10.49Review712026-06-09
0.10.48Review712026-06-09
0.10.47Review712026-06-09
0.10.46Review1022026-06-09
0.10.45Review1022026-06-08
0.10.44Review712026-06-08
0.10.43Review712026-06-08
0.10.42Review1022026-06-08
0.10.41Review712026-06-08
0.10.40Review1022026-06-05
0.10.39Review1022026-06-05
0.10.38Review1022026-06-05
0.10.37Review712026-06-05
0.10.36Review712026-06-04
0.10.35Review1022026-06-04
0.10.34Review712026-06-04
0.10.33Review1022026-06-03
0.10.32Review712026-06-03
0.10.31Review712026-06-03
0.10.30Review712026-06-03
0.10.29Review712026-06-03
0.10.28Review712026-06-03
0.10.27Review712026-06-03
0.10.26Review712026-06-02
0.10.25Review712026-06-02
0.10.23Review1022026-06-01
0.10.22Review712026-06-01
0.10.20Review712026-05-31
0.10.18Review712026-05-31
0.10.17Review1022026-05-31
0.10.12Review712026-05-31
0.10.6Review712026-05-30
0.9.18Review1022026-05-30
0.9.16Review1022026-05-30
0.9.15Review1022026-05-30
0.9.14Review1022026-05-30
0.10.5Review712026-05-30
0.10.4Review712026-05-30
0.10.3Review712026-05-30
0.10.2Review712026-05-30
0.9.19Review712026-05-30
0.9.12Review252026-05-28
0.9.13Review252026-05-28
0.9.10Review252026-05-27
0.9.11Review252026-05-27
0.9.7Review252026-05-26
0.9.8Review362026-05-26
0.9.1Review252026-05-26
0.9.2Review252026-05-26

Block this in CI

PkgRadar gates @aion0/forge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aion0/[email protected]