PkgRadar

npm · registry.npmjs.org

@yahaha-studio/kichi-forwarder

Remote Payload: matched "Curl "

Why PkgRadar flagged 0.1.2-beta.13

SeveritySignalEvidence
mediumRemote Payloadmatched "Curl " · package/config/kichi-config.json
mediumRemote Payloadmatched "Curl " · package/dist/config/kichi-config.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.2-beta.20Low risk02026-06-10
0.1.2-beta.19Low risk02026-06-08
0.1.2-beta.18Low risk02026-06-04
0.1.2-beta.17Low risk02026-05-29
0.1.2-beta.16Low risk02026-05-29
0.1.2-beta.15Low risk02026-05-28
0.1.2-beta.13Review242026-05-25
0.1.2-beta.14Review242026-05-25

Block this in CI

PkgRadar gates @yahaha-studio/kichi-forwarder (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @yahaha-studio/[email protected]