PkgRadar

npm · registry.npmjs.org

@zone-eu/wildduck

Remote Payload: matched "curl "

Why PkgRadar flagged 1.49.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/setup/01_install_commits.sh
mediumRemote Payloadmatched "curl " · package/setup/04_install_import_keys.sh
mediumRemote Payloadmatched "wget " · package/setup/05_install_packages.sh
mediumRemote Payloadmatched "wget " · package/setup/13_install_ssl_certs.sh
mediumRemote Payloadmatched "curl " · package/setup/15_install_deploy.sh
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/setup/get_install.sh
mediumRemote Payloadmatched "curl " · package/setup/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.49.4Review282026-06-11
1.49.3Review282026-06-10
1.49.2Review282026-06-10
1.49.1Review282026-06-04
1.49.0Review282026-06-04
1.48.1Review1202026-05-25
1.48.2Review1202026-05-25

Block this in CI

PkgRadar gates @zone-eu/wildduck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zone-eu/[email protected]