PkgRadar

npm · registry.npmjs.org

@chrome-devtools/node-app

Remote Payload: matched "cURL "

Why PkgRadar flagged 1.20260517.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · package/locales/af.json
mediumRemote Payloadmatched "cURL " · package/locales/am.json
mediumRemote Payloadmatched "cURL " · package/locales/ar.json
mediumRemote Payloadmatched "cURL " · package/locales/as.json
mediumRemote Payloadmatched "cURL " · package/locales/az.json
mediumRemote Payloadmatched "cURL " · package/locales/be.json
mediumRemote Payloadmatched "cURL " · package/locales/bg.json
mediumRemote Payloadmatched "cURL " · package/locales/bn.json
mediumRemote Payloadmatched "cURL " · package/locales/bs.json
mediumRemote Payloadmatched "cURL " · package/locales/ca.json
mediumRemote Payloadmatched "cURL " · package/locales/cs.json
mediumRemote Payloadmatched "iwr " · package/locales/cy.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.20260531.0Low risk02026-05-31
1.20260517.0Review722026-05-24
1.20260524.0Review722026-05-24

Block this in CI

PkgRadar gates @chrome-devtools/node-app (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @chrome-devtools/[email protected]
@chrome-devtools/node-app — npm security scan | PkgRadar