PkgRadar

npm · registry.npmjs.org

@gnpdev/rpa-tools

Remote Payload: matched "cUrl "

Why PkgRadar flagged 1.5.18

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/src/gateway.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.21Low risk02026-06-14
1.5.19Low risk02026-06-14
1.5.20Low risk02026-06-14
1.5.18Review122026-06-14
1.5.17Review122026-06-14
1.5.15Low risk02026-06-14
1.5.16Low risk02026-06-14
1.5.14Low risk02026-06-14
1.5.13Low risk02026-06-14
1.5.12Low risk02026-06-14
1.5.11Low risk02026-06-14
1.5.10Low risk02026-06-14
1.5.8Low risk02026-06-14
1.5.7Low risk02026-06-14
1.5.6Low risk02026-06-13
1.5.4Low risk02026-06-13
1.5.3Low risk02026-06-13
1.5.2Low risk02026-06-12
1.5.0Low risk02026-06-05
1.1.4Low risk02026-06-04
1.3.0Low risk02026-06-04

Block this in CI

PkgRadar gates @gnpdev/rpa-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gnpdev/[email protected]