PkgRadar

npm · registry.npmjs.org

@xdarkicex/openclaw-memory-libravdb

Remote Payload: matched "cURL "

Why PkgRadar flagged 1.6.19

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · package/dist/index.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.9.8Low risk02026-06-12
1.9.7Low risk02026-06-10
1.9.6Low risk02026-06-10
1.9.4Low risk02026-06-08
1.9.3Low risk02026-06-08
1.9.2Low risk02026-06-08
1.9.1Low risk02026-06-07
1.9.0Low risk02026-06-07
1.8.12Low risk02026-06-06
1.8.11Low risk02026-06-06
1.8.10Low risk02026-06-04
1.8.9Low risk02026-06-02
1.8.8Low risk02026-06-01
1.8.7Low risk02026-06-01
1.8.6Low risk02026-06-01
1.8.5Low risk02026-06-01
1.8.4Low risk02026-06-01
1.8.3Low risk02026-06-01
1.8.1Low risk02026-06-01
1.8.2Low risk02026-06-01
1.8.0Low risk02026-05-31
1.7.0Low risk02026-05-30
1.6.32Low risk02026-05-29
1.6.31Low risk02026-05-29
1.6.29Low risk02026-05-29
1.6.30Low risk02026-05-29
1.6.28Low risk02026-05-29
1.6.27Low risk02026-05-29
1.6.25Low risk02026-05-25
1.6.22Low risk02026-05-25
1.6.23Low risk02026-05-25
1.6.20Low risk02026-05-25
1.6.19Review122026-05-24
1.6.18Review122026-05-24

Block this in CI

PkgRadar gates @xdarkicex/openclaw-memory-libravdb (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @xdarkicex/[email protected]