PkgRadar

npm · registry.npmjs.org

@proxysoul/soulforge

Remote Payload: matched "curl "

Why PkgRadar flagged 2.18.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 2.18.0 vs 2.17.0: "bun scripts/postinstall.mjs" · package.json
mediumRemote Payloadmatched "curl " · package/dist/bin.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.20.15Review52026-06-12
2.20.14Review52026-06-12
2.20.13Review52026-06-11
2.20.12Review52026-06-11
2.18.0High risk572026-06-10
2.20.11Review52026-06-09
2.20.10Review52026-06-09
2.20.9Review52026-06-09
2.20.8Review52026-06-08
2.20.4Review52026-06-08
2.20.7Review52026-06-08
2.20.5Review52026-06-04
2.20.6Review52026-06-04
2.20.2Review52026-06-03
2.20.3Review52026-06-03
2.20.1Review52026-06-03
2.20.0Review52026-06-02
2.19.0Review52026-05-31
2.18.6Review52026-05-30
2.18.5Review52026-05-30
2.18.3Review112026-05-27
2.18.4Review112026-05-27
2.18.1Review142026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates @proxysoul/soulforge (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @proxysoul/[email protected]