PkgRadar

npm · registry.npmjs.org

@lacymorrow/shipx

Remote Payload: matched "github.com/${repoSlug}/releases/download"

Why PkgRadar flagged 0.1.14

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/${repoSlug}/releases/download" · package/dist/cli.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.17Low risk02026-06-04
0.1.15Low risk02026-05-25
0.1.16Low risk02026-05-25
0.1.14Review122026-05-24
0.1.12Low risk02026-05-24
0.1.13Review122026-05-24

Block this in CI

PkgRadar gates @lacymorrow/shipx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lacymorrow/[email protected]