PkgRadar

npm · registry.npmjs.org

@ledgerhq/coin-tester-bitcoin

Remote Payload: matched "curl "

Why PkgRadar flagged 1.10.3-nightly.20260527030754

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/src/docker/docker-compose.yml

Scanned versions

VersionVerdictScoreScanned (UTC)
1.10.5-nightly.20260612030643Low risk02026-06-12
1.10.5Low risk02026-06-11
1.10.5-nightly.20260611030748Low risk02026-06-11
1.10.5-nightly.20260610030722Low risk02026-06-10
1.10.5-nightly.20260609030647Low risk02026-06-09
1.10.5-nightly.20260606030643Low risk02026-06-06
1.10.4-nightly.20260605030615Low risk02026-06-05
1.10.4Low risk02026-06-04
1.10.4-nightly.20260604030755Low risk02026-06-04
1.10.4-nightly.20260603081117Low risk02026-06-03
1.10.4-nightly.20260603030820Low risk02026-06-03
1.10.4-nightly.20260602030710Low risk02026-06-02
1.10.4-nightly.20260530030617Low risk02026-05-30
1.10.4-nightly.20260529145638Low risk02026-05-29
1.10.4-nightly.20260529151329Low risk02026-05-29
1.10.3-nightly.20260529072926Low risk02026-05-29
1.10.3-nightly.20260529030713Low risk02026-05-29
1.10.3Low risk02026-05-28
1.10.3-nightly.20260528030659Low risk02026-05-28
1.10.3-nightly.20260527030754Review82026-05-27
1.10.3-nightly.20260526030636Review82026-05-26
1.10.3-nightly.20260523030637Review82026-05-26

Block this in CI

PkgRadar gates @ledgerhq/coin-tester-bitcoin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @ledgerhq/[email protected]