PkgRadar

npm · registry.npmjs.org

@c4t4/heyamigo

Remote Payload: matched "curl "

Why PkgRadar flagged 0.10.7

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/scripts/start-browser.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.7Review32026-05-28
0.10.5Review32026-05-27
0.10.6Review32026-05-27
0.10.4Review32026-05-25
0.10.2Review32026-05-25
0.10.3Review32026-05-25
0.9.20Review242026-05-25
0.9.19Review242026-05-25
0.9.18Review242026-05-25
0.9.17Review242026-05-25
0.9.16Review242026-05-25
0.9.15Review242026-05-25
0.9.14Review242026-05-25
0.9.13Review242026-05-25
0.9.12Review242026-05-25
0.9.11Review242026-05-25
0.9.10Review242026-05-25
0.9.9Review242026-05-25
0.9.8Review242026-05-25
0.9.7Review242026-05-25
0.9.6Review242026-05-25
0.9.5Review242026-05-25
0.9.4Review242026-05-25
0.9.3Review242026-05-25
0.9.2Review242026-05-25
0.9.1Review242026-05-25
0.9.0Review242026-05-25
0.8.15Review242026-05-24
0.8.14Review242026-05-24
0.8.13Review242026-05-24
0.8.12Review242026-05-24
0.8.11Review242026-05-24
0.8.10Review242026-05-24
0.8.9Review242026-05-24
0.8.8Review242026-05-24
0.8.7Review242026-05-24

Block this in CI

PkgRadar gates @c4t4/heyamigo (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @c4t4/[email protected]