PkgRadar

npm · registry.npmjs.org

@miller-tech/uap

Remote Payload: matched "curl "

Why PkgRadar flagged 1.38.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/cli/rtk.js
mediumRemote Payloadmatched "curl " · package/dist/memory/serverless-qdrant.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.38.0Review272026-06-13
1.37.0Review272026-06-13
1.36.1Review272026-06-13
1.36.0Review272026-06-13
1.35.0Review272026-06-12
1.33.0Review272026-06-12
1.34.0Review272026-06-12
1.31.0Review272026-06-12
1.32.0Review272026-06-12
1.30.1Review272026-06-12
1.30.0Review272026-06-12
1.29.0Review272026-06-12
1.28.0Review272026-06-12
1.27.0Review232026-06-12
1.26.6Review232026-06-01
1.26.5Review232026-05-31
1.26.4Review232026-05-31
1.26.3Review232026-05-31
1.26.2Review232026-05-31
1.26.1Review232026-05-31
1.22.0Review202026-05-31
1.26.0Review232026-05-31

Block this in CI

PkgRadar gates @miller-tech/uap (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @miller-tech/[email protected]