npm · registry.npmjs.org
claudeup
Remote Payload: matched "raw.githubusercontent.com"
Why PkgRadar flagged 4.17.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/src/services/plugin-manager.js |
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/src/services/skills-manager.js |
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/src/services/plugin-manager.ts |
| medium | Remote Payload | matched "raw.githubusercontent.com" · package/src/services/skills-manager.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.17.0 | Review | 17 | 2026-06-03 |
4.18.0 | Review | 17 | 2026-06-03 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]