PkgRadar

npm · registry.npmjs.org

@serve.zone/catalog

Known Indicator Filename: package/dist_bundle/bundle.js

Why PkgRadar flagged 2.12.6

SeveritySignalEvidence
highKnown Indicator Filenamepackage/dist_bundle/bundle.js · package/dist_bundle/bundle.js
highKnown Indicator Filenamepackage/dist_watch/bundle.js · package/dist_watch/bundle.js
mediumLarge Javascript Payload5769979 bytes · package/dist_bundle/bundle.js
mediumLarge Javascript Payload9838060 bytes · package/dist_watch/bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.14.0Low risk02026-06-06
2.13.0Low risk02026-06-04
2.12.8Low risk02026-06-03
2.12.7Low risk02026-05-28
2.12.6Review1102026-05-24
2.12.4Review1102026-05-24
2.12.5Review1102026-05-24

Related campaigns

Block this in CI

PkgRadar gates @serve.zone/catalog (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @serve.zone/[email protected]
@serve.zone/catalog — npm security scan | PkgRadar