PkgRadar

npm · registry.npmjs.org

@extension.dev/mcp

Remote Payload: matched "github.com/extension-js/examples/releases/download"

Why PkgRadar flagged 3.17.0

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/extension-js/examples/releases/download" · package/dist/module.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.17.0Review122026-06-12
3.17.0-canary.1779907011.abb3f15Review122026-06-12
3.17.0-canary.1779907478.8ba1b78Review122026-05-27
3.17.0-canary.1779910200.ddcd9ebReview122026-05-27

Block this in CI

PkgRadar gates @extension.dev/mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @extension.dev/[email protected]