PkgRadar

npm · registry.npmjs.org

@icyfenix-dmla/cli

Remote Payload: matched "wget "

Why PkgRadar flagged 2026.5.25-736

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/src/commands/data.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.12-1043Low risk02026-06-12
2026.6.11-2135Low risk02026-06-11
2026.6.11-2036Low risk02026-06-11
2026.6.11-2018Low risk02026-06-11
2026.6.11-2001Low risk02026-06-11
2026.6.11-1945Low risk02026-06-11
2026.6.11-1919Low risk02026-06-11
2026.6.6-1021Low risk02026-06-06
2026.6.5-2055Low risk02026-06-05
2026.6.5-2100Low risk02026-06-05
2026.6.5-1204Low risk02026-06-05
2026.6.5-1719Low risk02026-06-05
2026.5.29-2149Low risk02026-05-29
2026.5.29-2018Low risk02026-05-29
2026.5.25-736Review122026-05-24
2026.5.24-2151Review122026-05-24
2026.5.24-2045Review122026-05-24
2026.5.24-16Review122026-05-24
2026.5.24-1015Review122026-05-24

Block this in CI

PkgRadar gates @icyfenix-dmla/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @icyfenix-dmla/[email protected]