PkgRadar

npm · registry.npmjs.org

@polderlabs/bizar

Remote Payload: matched "curl "

Why PkgRadar flagged 3.0.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/cli/copy.mjs
mediumRemote Payloadmatched "curl " · package/cli/install.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.0Review292026-06-20
2.6.1Review292026-06-20
2.6.0Review292026-06-20
2.4.0Review292026-06-20
2.3.0Review292026-06-20
3.5.4Review242026-06-19
3.5.2Review242026-06-19
3.5.1Review242026-06-19
3.5.0Review242026-06-19
3.4.1Review242026-06-19
3.3.3Review242026-06-19
3.3.1Review242026-06-19
3.3.2Review242026-06-19
3.3.0Review242026-06-19
3.2.2Review242026-06-19
3.2.1Review292026-06-19
3.2.0Review292026-06-19
3.1.1Review292026-06-19
3.0.2Review292026-06-19
3.0.1Review392026-06-19

Block this in CI

PkgRadar gates @polderlabs/bizar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @polderlabs/[email protected]