PkgRadar

npm · registry.npmjs.org

@getmonoceros/workbench

Remote Payload: matched "curl "

Why PkgRadar flagged 1.7.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/bin.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/bin.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/features/atlassian/devcontainer-feature.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/features/claude-code/devcontainer-feature.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/features/github-cli/devcontainer-feature.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.21.2Low risk02026-06-10
1.21.1Low risk02026-06-10
1.21.0Low risk02026-06-10
1.20.2Low risk02026-06-10
1.20.1Low risk02026-06-10
1.20.0Low risk02026-06-10
1.19.2Low risk02026-06-10
1.19.1Low risk02026-06-10
1.19.0Low risk02026-06-09
1.18.0Low risk02026-06-09
1.17.1Low risk02026-06-09
1.17.0Low risk02026-06-09
1.16.2Low risk02026-06-06
1.16.1Low risk02026-06-06
1.16.0Low risk02026-06-06
1.15.0Low risk02026-06-04
1.14.0Low risk02026-06-03
1.14.1Low risk02026-06-03
1.13.3Low risk02026-06-03
1.13.2Low risk02026-06-03
1.13.1Low risk02026-06-03
1.13.0Low risk02026-06-02
1.11.11Low risk02026-06-01
1.12.0Low risk02026-06-01
1.11.10Low risk02026-06-01
1.11.9Low risk02026-06-01
1.11.8Low risk02026-05-31
1.11.7Low risk02026-05-31
1.11.6Low risk02026-05-31
1.11.5Low risk02026-05-31
1.11.4Low risk02026-05-31
1.11.3Low risk02026-05-31
1.11.2Low risk02026-05-31
1.11.1Low risk02026-05-31
1.11.0Low risk02026-05-31
1.10.1Low risk02026-05-30
1.10.0Low risk02026-05-28
1.9.6Low risk02026-05-27
1.9.7Low risk02026-05-27
1.7.5Low risk02026-05-25
1.7.4Review122026-05-24
1.7.3Review122026-05-24
1.7.2Review122026-05-24
1.7.1Review122026-05-24
1.7.0Review122026-05-24
1.6.12Review122026-05-24
1.6.11Review122026-05-24
1.6.9Review122026-05-24
1.6.10Review122026-05-24

Block this in CI

PkgRadar gates @getmonoceros/workbench (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @getmonoceros/[email protected]