PkgRadar

npm · registry.npmjs.org

@kkelly-offical/kkcode

Remote Payload: matched "wget "

Why PkgRadar flagged 0.2.3

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/src/permission/exec-policy.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/src/github/flow.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0Low risk02026-05-31
0.2.5Low risk02026-05-27
0.2.6Low risk02026-05-27
0.2.3Review122026-05-24
0.2.4-preview.1Review122026-05-24

Related campaigns

Block this in CI

PkgRadar gates @kkelly-offical/kkcode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kkelly-offical/[email protected]