PkgRadar

npm · registry.npmjs.org

@delorenj/pjangler

Remote Payload: matched "curl "

Why PkgRadar flagged 1.1.5

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/templates/hermes-agent/template/.scripts/30-telegram.sh
mediumRemote Payloadmatched "curl " · package/templates/hermes-agent/template/.scripts/40-plane.sh
mediumRemote Payloadmatched "curl " · package/templates/hermes-agent/template/.scripts/providers/plane.sh
mediumRemote Payloadmatched "curl " · package/templates/hermes-agent/template/.scripts/providers/trello.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.5Review532026-06-05
1.1.3Review532026-06-05
1.1.4Review532026-06-05
1.1.2Review652026-06-05
1.1.1Low risk02026-06-01

Block this in CI

PkgRadar gates @delorenj/pjangler (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @delorenj/[email protected]