PkgRadar

npm · registry.npmjs.org

@koordinates/mapnik

Remote Payload: matched "curl "

Why PkgRadar flagged 4.99.35

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/deps/wagyu/mason.sh
highRemote Dependency Specdependencies.mapnik-vector-tile="https://github.com/mapbox/mapnik-vector-tile/tarball/98ace1c737c6c9a80058835d41de233621394678" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
4.99.35High risk222026-06-10
4.99.38Review142026-05-30
4.99.39Review142026-05-29

Block this in CI

PkgRadar gates @koordinates/mapnik (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @koordinates/[email protected]