PkgRadar

npm · registry.npmjs.org

@exodus/secp256k1

Remote Dependency Spec: devDependencies.prebuildify-cross="github:prebuild/prebuildify-cross#v4.0.0"

Why PkgRadar flagged 5.0.0-exodus.8

SeveritySignalEvidence
mediumRemote Dependency SpecdevDependencies.prebuildify-cross="github:prebuild/prebuildify-cross#v4.0.0" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.0-exodus.8Review52026-06-08
5.0.0-hybrid.0Review52026-06-08
5.0.0-exodus.4.patch.1Low risk02026-05-27
5.0.0-exodus.4.patch.2Low risk02026-05-27

Block this in CI

PkgRadar gates @exodus/secp256k1 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @exodus/[email protected]