PkgRadar

npm · registry.npmjs.org

@codeyam/codeyam-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 0.1.37

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/codeyam-cli/src/webserver/build/server/assets/server-build-CNvgz1cC.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.37Review52026-06-08
0.1.0-staging.c21fa76Review52026-06-08
0.1.0-staging.b49802dReview52026-06-02
0.1.36Review52026-06-02
0.1.0-staging.fff1b4eReview52026-06-02
0.1.35Review52026-06-02
0.1.34Review52026-06-02
0.1.0-staging.121e983Review52026-06-02

Block this in CI

PkgRadar gates @codeyam/codeyam-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @codeyam/[email protected]