PkgRadar

npm · registry.npmjs.org

@shmulikdav/solix

Remote Payload: matched "curl "

Why PkgRadar flagged 1.5.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/hooks/notification.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/post-tool.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/pre-tool-bash.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/pre-tool-file.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/pre-tool-task.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/prompt-submit.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/session-start.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/stop.sh
mediumRemote Payloadmatched "curl " · package/dist/hooks/subagent-stop.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.5.0Review502026-05-24
1.8.0Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates @shmulikdav/solix (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @shmulikdav/[email protected]