PkgRadar

npm · registry.npmjs.org

bloby-bot

Remote Payload: matched "curl "

Why PkgRadar flagged 0.70.13

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bin/cli.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/supervisor/index.ts
mediumRemote Payloadmatched "curl " · package/supervisor/tunnel.ts
mediumCredential file accessmatched ".npmrc" · package/bin/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.70.13Review512026-06-17
0.70.12Review352026-06-11
0.70.10Review352026-06-11
0.70.11Review512026-06-11
0.70.9Review352026-06-11
0.70.8Review352026-06-11
0.70.5Review352026-06-11
0.70.6Review352026-06-11
0.70.4Review352026-06-11
0.70.1Review512026-06-11
0.70.0Review352026-06-11
0.69.6Review352026-06-11
0.69.5Review352026-06-10
0.69.3Review352026-06-10
0.69.4Review352026-06-10
0.69.2Review352026-06-10
0.69.0Review352026-06-10
0.69.1Review512026-06-10
0.68.4Review352026-06-10
0.68.3Review352026-06-10
0.68.2Review512026-06-10
0.68.1Review512026-06-10
0.68.0Review352026-06-10
0.67.0Review352026-06-10
0.66.1Review442026-06-10
0.66.0Review442026-06-10
0.65.4Review442026-06-10
0.65.3Review442026-06-10
0.65.2Review442026-06-10
0.65.0Review442026-06-09
0.64.0Review442026-06-09
0.63.0Review442026-06-09
0.62.3Review442026-06-09
0.62.0Review442026-06-09
0.61.0Review352026-06-09
0.60.1Review512026-06-08
0.60.0Review512026-06-08
0.59.0Review512026-06-08
0.58.0Review352026-06-08
0.57.0Review352026-06-08
0.56.0Review352026-06-02
0.56.1Review352026-06-02
0.55.0Review352026-06-02
0.54.12Review352026-06-02
0.54.11Review352026-05-30
0.54.10Review512026-05-30
0.53.10Review352026-05-29
0.53.9Review352026-05-29
0.53.7Review352026-05-29
0.53.8Review352026-05-29
0.53.1Review512026-05-29
0.53.2Review352026-05-29
0.51.5Review282026-05-28
0.51.3Review402026-05-27
0.51.4Review402026-05-27

Block this in CI

PkgRadar gates bloby-bot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]