PkgRadar

npm · registry.npmjs.org

@embedreach/components

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.3.47

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/chunks/sandbox-loading-screen.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.12Low risk02026-06-17
0.3.47Review62026-06-17
0.3.48Review62026-06-17
0.3.49Review62026-06-17
0.3.50Review62026-06-17

Block this in CI

PkgRadar gates @embedreach/components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @embedreach/[email protected]