npm · registry.npmjs.org
@hatchway/cli
Remote Payload, Tls Verification Disabled, Credential file access
Why PkgRadar flagged 0.50.72
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | package/dist/chunks/auto-update-Ddo5Ntt7.js |
| medium | Remote Payload | package/dist/chunks/manager-0U0BIO9r.js |
| medium | Tls Verification Disabled | package/dist/chunks/port-allocator-DAjm7X-F.js |
| medium | Remote Payload | package/dist/chunks/upgrade-BBpJirEu.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.50.72 | Review | 44 | 2026-06-21 |
0.50.71 | Review | 56 | 2026-06-21 |
0.50.67 | Review | 44 | 2026-06-20 |
0.50.68 | Review | 44 | 2026-06-20 |
0.50.69 | Review | 44 | 2026-06-20 |
0.50.70 | Review | 56 | 2026-06-20 |
Block this in CI
pkgradar gate --ecosystem npm @hatchway/[email protected]