PkgRadar

npm · registry.npmjs.org

@hyperdag/trustshell

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.6.0

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/cli/commands/attestation.js
mediumRemote Payloadmatched "cUrl " · package/dist/x402/client.js
mediumRemote Payloadmatched "cUrl " · package/dist/cli/commands/pay.js
mediumRemote Payloadmatched "cUrl " · package/dist/reputation.js
mediumRemote Payloadmatched "cUrl " · package/dist/cli/commands/whois.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.0Review502026-05-24
0.6.1Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates @hyperdag/trustshell (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hyperdag/[email protected]