PkgRadar

npm · registry.npmjs.org

@bniladridas/cursor

Remote Payload: matched "github.com/bniladridas/cursor/releases/download"

Why PkgRadar flagged 0.1.10

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/bniladridas/cursor/releases/download" · package/install.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.10Review172026-06-20
0.1.11Review172026-06-20
0.1.9Review172026-06-20
0.1.8Review172026-06-20
0.1.7Review172026-06-20
0.1.21Review292026-06-19
0.1.20Review292026-06-19
0.1.19Review292026-06-19
0.1.18Review292026-06-19
0.1.17Review292026-06-19
0.1.16Review292026-06-19
0.1.14Review172026-06-19
0.1.15Review292026-06-19
0.1.13Review172026-06-19
0.1.12Review172026-06-19

Block this in CI

PkgRadar gates @bniladridas/cursor (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bniladridas/[email protected]