PkgRadar

npm · registry.npmjs.org

codexmate

Remote Payload: matched "curl "

Why PkgRadar flagged 0.0.52

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/cli/update.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.52Review122026-06-17
0.0.51Review122026-06-15
0.0.50Review122026-06-14
0.0.49Review122026-06-13
0.0.48Review122026-06-11
0.0.47Review122026-06-07
0.0.45Review122026-06-06
0.0.44Review122026-06-04
0.0.43Review122026-06-04
0.0.42Review122026-06-03
0.0.41Review122026-06-01
0.0.40Review122026-05-31
0.0.39Review82026-05-30
0.0.38Review122026-05-29
0.0.37Review242026-05-28
0.0.36Review242026-05-26
0.0.33Review122026-05-24
0.0.34Review122026-05-24

Block this in CI

PkgRadar gates codexmate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]