PkgRadar

npm · registry.npmjs.org

@eugeniomatteus/cli

Remote Payload: matched "Invoke-WebRequest"

Why PkgRadar flagged 1.0.0

SeveritySignalEvidence
mediumRemote Payloadmatched "Invoke-WebRequest" · package/.merlin-core/core/execution/env-preflight.js
mediumRemote Payloadmatched "curl " · package/.merlin-core/tools/vps-security-audit.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0Review242026-06-10

Block this in CI

PkgRadar gates @eugeniomatteus/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @eugeniomatteus/[email protected]