PkgRadar

npm · registry.npmjs.org

@aliwey/bmo

Remote Payload: matched "curl "

Why PkgRadar flagged 2.1.15

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/webchat/node_modules/better-sqlite3/deps/download.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.15Review172026-06-06
2.1.14Review172026-06-06
2.1.13Review172026-06-06
2.1.12Review172026-06-06
2.1.11Review172026-06-06
2.1.10Review172026-06-06
2.1.9Review172026-06-06
2.1.8Review172026-06-06
2.1.7Review52026-06-06
2.1.6Review52026-06-06
2.1.5Review52026-06-06
2.1.4Review52026-06-06
2.1.3Review52026-06-06
2.1.2Review52026-06-06
2.1.1Review52026-06-06
2.1.0Review52026-06-06
2.0.9Review52026-06-06
2.0.8Review52026-06-06
2.0.7Review52026-06-06
2.0.6Review52026-06-06
2.0.5Review52026-06-06
2.0.3Review52026-06-06
2.0.4Review52026-06-06
2.0.2Review52026-06-06
2.0.0Review52026-06-06
2.0.1Review52026-06-06

Block this in CI

PkgRadar gates @aliwey/bmo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aliwey/[email protected]