PkgRadar

npm · registry.npmjs.org

alchemylab-opencode

Remote Payload: matched "github.com/BurntSushi/ripgrep/releases/download"

Why PkgRadar flagged 1.0.16

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-5JK6OKSA.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-F4FEYYJN.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-GNXOGOVC.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-L3MXQ7IO.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-LFWHPFNU.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-MMTZESVG.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-QBFXKT25.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-TREWRWAQ.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-UKQIL5XA.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-W7LNDS5C.js
mediumRemote Payloadmatched "github.com/BurntSushi/ripgrep/releases/download" · package/dist/chunk-YRSS72CF.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.16Review1002026-05-28
1.0.17Review1002026-05-28

Block this in CI

PkgRadar gates alchemylab-opencode (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]