PkgRadar

npm · registry.npmjs.org

@circlesac/vlt-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 26.6.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bin/install.sh
mediumNew Account With Lifecycle Hookpackage first published 83 day(s) ago, 10 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
26.6.2Review52026-06-12
26.6.1Review52026-06-12
26.5.1Review52026-06-12
26.5.2Review52026-06-12
26.5.3Review52026-06-12
26.6.0Review52026-06-12

Block this in CI

PkgRadar gates @circlesac/vlt-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @circlesac/[email protected]