PkgRadar

npm · registry.npmjs.org

clew-code

Remote Payload: matched "curl "

Why PkgRadar flagged 0.2.33

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bin/clew.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.33Review122026-06-17
0.2.32Review82026-06-17
0.2.31Review82026-06-17
0.2.30Review82026-06-17
0.2.29Review122026-06-17
0.2.28Review122026-06-16
0.2.27Review122026-06-15
0.2.26Review82026-06-15
0.2.24Low risk02026-06-15
0.2.25Review82026-06-15
0.2.23Low risk02026-06-15
0.2.22Low risk02026-06-14
0.2.20Low risk02026-06-14
0.2.21Low risk02026-06-14
0.2.19Low risk02026-06-14
0.2.18Low risk02026-06-14
0.2.16Low risk02026-06-14
0.2.14Low risk02026-06-14
0.2.15Low risk02026-06-14
0.2.13Low risk02026-06-13
0.2.11Low risk02026-06-13
0.2.10Low risk02026-06-13
0.2.9Low risk02026-06-13
0.2.8Low risk02026-06-13
0.2.7Low risk02026-06-11
0.2.6Low risk02026-06-10
0.2.5Low risk02026-06-10
0.2.2Low risk02026-06-08
0.2.4Low risk02026-06-08
0.2.1Low risk02026-06-06

Block this in CI

PkgRadar gates clew-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]