PkgRadar

npm · registry.npmjs.org

braintrust

Remote Payload: matched "cUrl "

Why PkgRadar flagged 3.17.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 3.17.0 vs 3.16.0: "node ./scripts/install.js" · package.json
mediumRemote Payloadmatched "cUrl " · package/dist/browser.js
mediumRemote Payloadmatched "cUrl " · package/dist/edge-light.js
mediumRemote Payloadmatched "cUrl " · package/dist/workerd.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.17.0High risk812026-06-10
3.16.0Review102026-06-03
3.15.0Review102026-06-01
3.14.0Review102026-05-29
3.13.0Review142026-05-28
3.11.0Low risk02026-05-26
3.12.0Review142026-05-26

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates braintrust (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]