PkgRadar

npm · registry.npmjs.org

@cryptsmile/forgeai

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 1.1.0

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/.next/standalone/.next/server/chunks/_0pgzd98._.js
mediumRemote Payloadmatched "github.com/FiloSottile/mkcert/releases/download" · package/.next/standalone/node_modules/next/dist/lib/mkcert.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0Review292026-05-31
1.0.3Review292026-05-30
1.0.2Review242026-05-27
1.0.1Review242026-05-27
0.1.0Review242026-05-26

Block this in CI

PkgRadar gates @cryptsmile/forgeai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cryptsmile/[email protected]