PkgRadar

npm · registry.npmjs.org

bluelamp

Remote Payload: matched "curl "

Why PkgRadar flagged 3.0.6

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 3.0.6 vs 3.0.5: "node scripts/setup-agents.js && node scripts/generate-bluelamp-links.js" · package.json
mediumRemote Payloadmatched "curl " · package/knowledge-injection/hooks/inject-encrypted.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
6.4.10Low risk02026-06-17
6.4.9Low risk02026-06-13
6.4.8Low risk02026-06-13
4.3.4Review32026-06-12
6.4.7Low risk02026-06-12
6.4.6Low risk02026-06-12
3.0.7Review112026-06-12
3.0.6High risk572026-06-12
3.0.9High risk572026-06-12
6.4.5Low risk02026-06-12
6.4.4Low risk02026-06-03
6.4.3Low risk02026-06-02
6.4.2Low risk02026-05-30
6.4.0Review32026-05-30
6.4.1Review32026-05-30

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates bluelamp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
bluelamp — npm security scan | PkgRadar