PkgRadar

npm · registry.npmjs.org

codeprobe-scanner

Remote Payload: matched "curl "

Why PkgRadar flagged 2.0.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bin/codeprobe.cjs
mediumRemote Payloadmatched "curl " · package/bin/install-and-run.sh
mediumSuspicious Publish Context{"package_age_days":0,"publisher":"nachikethreddyy","burst_same_day":1,"burst_week":1,"lure":null,"version_anomaly":false,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0Review342026-06-13
1.0.22Review342026-06-13
1.0.20Review342026-06-13
1.0.21Review342026-06-13
1.0.19Review342026-06-13
1.0.17Review342026-06-13
1.0.16Review342026-06-13
1.0.15Review342026-06-13
1.0.14Review342026-06-13
1.0.12Review342026-06-13
1.0.13Review342026-06-13
1.0.11Review342026-06-13
1.0.10Review342026-06-13
1.0.9Review342026-06-13
1.0.8Review342026-06-13
1.0.7Review342026-06-13
1.0.6Review342026-06-13
1.0.5Review342026-06-13
1.0.4Review342026-06-13
1.0.2Review222026-06-13
1.0.3Review342026-06-13
1.0.1Review222026-06-13
1.0.0Review222026-06-13

Block this in CI

PkgRadar gates codeprobe-scanner (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]