PkgRadar

npm · registry.npmjs.org

china-mobile-international-custom-components

Remote Payload: matched "cURL "

Why PkgRadar flagged 0.1.75

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.BTtOI4Lb.js
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.BTVGZIT_.js
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.C1Vvw0yj.js
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.CJh1cruP.js
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.CqUxuiae.js
mediumRemote Payloadmatched "cURL " · package/es/chunks/WorkflowComponent.DdEOPat_.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.81Low risk02026-06-12
0.1.80Low risk02026-06-12
0.1.78Low risk02026-06-12
0.1.79Low risk02026-06-12
0.1.77Low risk02026-06-05
0.1.75Review502026-05-26
0.1.76Review502026-05-26

Block this in CI

PkgRadar gates china-mobile-international-custom-components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]