PkgRadar

npm · registry.npmjs.org

botmux

Remote Payload: matched "curl "

Why PkgRadar flagged 2.82.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/setup/ensure-herdr.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.82.1Review122026-06-17
2.82.0Review82026-06-16
2.81.1Review122026-06-16
2.81.0Review122026-06-16
2.80.0Review122026-06-16
2.79.1Review122026-06-16
2.79.0Review82026-06-16
2.78.0Review82026-06-16
2.77.0Review82026-06-16
2.76.0Review122026-06-15
2.76.1Review122026-06-15
2.75.1Review122026-06-15
2.75.0Review82026-06-13
2.74.0Review82026-06-13
2.73.0Review82026-06-13
2.72.0Review82026-06-13
2.71.5Review82026-06-12
2.71.4Review82026-06-12
2.71.3Review122026-06-11
2.71.2Review82026-06-11
2.71.1Review122026-06-11
2.71.0Review122026-06-11
2.70.0Review82026-06-11
2.69.0Review82026-06-11
2.68.1Review122026-06-11
2.68.0Review82026-06-11
2.67.1Review82026-06-11
2.67.0Review82026-06-11
2.67.0-canary.0Review82026-06-10
2.66.2Review82026-06-10
2.66.2-canary.0Review122026-06-10
2.66.1Review82026-06-10
2.66.0Review122026-06-10
2.66.0-canary.1Review82026-06-09
2.66.0-canary.0Review82026-06-09
2.65.0Review82026-06-07
2.64.0Review82026-06-06
2.63.1Review122026-06-05
2.63.0Review122026-06-05
2.62.0Review82026-06-05
2.61.0Review82026-06-05
2.60.1Review82026-06-05
2.60.0Review82026-06-05
2.60.0-canary.4Review122026-06-04
2.60.0-canary.3Review82026-06-04
2.60.0-canary.2Review122026-06-04
2.60.0-canary.1Review82026-06-04
2.60.0-canary.0Review122026-06-04
2.59.0-canary.0Review82026-06-03
2.59.0Review82026-06-03
2.58.0Review82026-06-03
2.58.0-canary.0Review122026-06-03
2.57.0Review82026-06-03
2.57.1Review82026-06-03
2.56.0Review122026-06-02
2.56.0-canary.0Low risk02026-06-02
2.55.0Low risk02026-06-02
2.54.0Low risk02026-06-02
2.53.0Low risk02026-06-01
2.52.0Low risk02026-06-01
2.51.1Low risk02026-06-01
2.51.0Low risk02026-05-30
2.50.0Low risk02026-05-30
2.49.0Low risk02026-05-29
2.48.3Low risk02026-05-29
2.48.2Low risk02026-05-29
2.49.0-canary.1Low risk02026-05-29
2.48.1Low risk02026-05-29
2.47.3Low risk02026-05-28
2.48.0Low risk02026-05-28
2.43.0-canary.5Review122026-05-28
2.45.0Review82026-05-28
2.43.0Review122026-05-28
2.44.0Review122026-05-28
2.43.0-canary.2Review82026-05-27
2.43.0-canary.3Review82026-05-27
2.41.0Review82026-05-26
2.42.0Review82026-05-26
2.40.0Review82026-05-26
2.41.0-canary.0Review122026-05-26
2.40.0-canary.0Review122026-05-26
2.39.1Review82026-05-26
2.39.0Review82026-05-26
2.38.0Review82026-05-25
2.38.1Review122026-05-25
2.37.1Review82026-05-25
2.38.0-canary.0Review82026-05-25
2.36.1Review242026-05-25
2.37.0-canary.0Review242026-05-25
2.36.0Review342026-05-25
2.36.0-canary.1Review342026-05-25
2.35.1Review342026-05-25
2.35.0Review342026-05-25
2.34.0Review342026-05-25
2.36.0-canary.0Review342026-05-25

Block this in CI

PkgRadar gates botmux (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]