PkgRadar

npm · registry.npmjs.org

claude-mem-lite

Remote Payload: matched "curl "

Why PkgRadar flagged 2.84.2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/scripts/hook-launcher.mjs
mediumRemote Payloadmatched "curl " · package/install-metadata.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.99.0Low risk02026-06-12
2.98.0Low risk02026-06-12
2.97.0Low risk02026-06-12
2.96.0Low risk02026-06-09
2.95.1Low risk02026-06-09
2.95.0Low risk02026-06-09
2.94.0Low risk02026-06-08
2.93.0Low risk02026-06-08
2.91.0Low risk02026-06-04
2.92.0Low risk02026-06-04
2.90.0Low risk02026-06-03
2.90.1Low risk02026-06-03
2.89.0Low risk02026-06-02
2.88.0Low risk02026-06-02
2.87.0Low risk02026-06-02
2.86.0Low risk02026-06-02
2.85.0Low risk02026-06-02
2.84.2Review242026-05-25
2.84.1Review242026-05-25
2.83.2Review342026-05-25
2.84.0Review342026-05-25

Block this in CI

PkgRadar gates claude-mem-lite (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]