PkgRadar

npm · registry.npmjs.org

@hashicorp/react-code-block

Remote Payload: matched "curl "

Why PkgRadar flagged 6.5.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/utils/prism-utils/script-refresh-syntaxes.js

Scanned versions

VersionVerdictScoreScanned (UTC)
6.5.0Review32026-06-10
6.6.0Review32026-06-10
6.7.0Review32026-06-10
6.7.0-canary-20240624195037Review32026-06-10

Block this in CI

PkgRadar gates @hashicorp/react-code-block (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hashicorp/[email protected]