PkgRadar

npm · registry.npmjs.org

@n24q02m/mcp-core

Remote Payload: matched "cUrl "

Why PkgRadar flagged 1.15.0-beta.2

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/build/auth/delegated-oauth-app.js
mediumRemote Payloadmatched "cUrl " · package/build/auth/local-oauth-app.js
mediumRemote Payloadmatched "cUrl " · package/build/transport/local-server.js
mediumRemote Payloadmatched "cUrl " · package/build/relay/tool-helpers.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.18.0-beta.2Low risk02026-06-11
1.18.0-beta.1Low risk02026-06-10
1.17.5-beta.3Low risk02026-06-10
1.17.5-beta.2Low risk02026-06-10
1.17.5-beta.1Low risk02026-06-10
1.17.4Low risk02026-06-09
1.17.4-beta.1Low risk02026-06-09
1.17.3Low risk02026-06-07
1.17.3-beta.2Low risk02026-06-07
1.17.3-beta.1Low risk02026-06-07
1.17.2Low risk02026-06-01
1.17.2-beta.1Low risk02026-06-01
1.17.1Low risk02026-05-29
1.17.0Low risk02026-05-29
1.17.0-beta.1Low risk02026-05-29
1.16.0Low risk02026-05-28
1.16.0-beta.1Low risk02026-05-28
1.15.0Low risk02026-05-26
1.15.0-beta.3Low risk02026-05-26
1.15.0-beta.2Review482026-05-25
1.14.0Review482026-05-24
1.15.0-beta.1Review482026-05-24

Block this in CI

PkgRadar gates @n24q02m/mcp-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @n24q02m/[email protected]