PkgRadar

npm · registry.npmjs.org

@blockrun/clawrouter

Remote Payload: matched "curl "

Why PkgRadar flagged 0.12.197

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/scripts/reinstall.sh
mediumLarge Javascript Payload3292365 bytes · package/dist/cli.js
mediumLarge Javascript Payload3146293 bytes · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.208Low risk02026-06-11
0.12.207Low risk02026-06-11
0.12.63Low risk02026-06-10
0.12.206Low risk02026-06-10
0.12.205Low risk02026-06-08
0.12.204Low risk02026-06-08
0.12.203Low risk02026-06-06
0.12.202Low risk02026-06-06
0.12.201Low risk02026-06-06
0.12.200Low risk02026-06-01
0.12.199Low risk02026-05-31
0.12.198Low risk02026-05-29
0.12.197Review222026-05-27
0.12.195Review442026-05-24
0.12.196Review442026-05-24

Block this in CI

PkgRadar gates @blockrun/clawrouter (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @blockrun/[email protected]