PkgRadar

npm · registry.npmjs.org

@o-lang/llm-ollama

Remote Payload: matched "curl "

Why PkgRadar flagged 1.0.9

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/postinstall.js
mediumNew Account With Lifecycle Hookpackage first published 47 day(s) ago, 9 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.9Review172026-06-11
1.0.8Review172026-06-11
1.0.7Review172026-06-10
1.0.2Review172026-06-10
1.0.6Review172026-06-10
1.0.4Review172026-06-10
1.0.5Review172026-06-10

Block this in CI

PkgRadar gates @o-lang/llm-ollama (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @o-lang/[email protected]