npm · registry.npmjs.org
create-composure
Remote Payload: matched "curl "
Why PkgRadar flagged 1.4.20
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · package/dist/steps/04-install-claude.js |
| medium | Remote Payload | matched "curl " · package/src/steps/04-install-claude.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.4.20 | Review | 24 | 2026-06-02 |
1.4.19 | Review | 24 | 2026-06-02 |
1.4.18 | Review | 24 | 2026-06-01 |
1.4.17 | Review | 24 | 2026-06-01 |
1.4.16 | Review | 16 | 2026-05-31 |
1.4.15 | Review | 16 | 2026-05-31 |
1.4.14 | Review | 16 | 2026-05-31 |
1.4.13 | Review | 16 | 2026-05-29 |
1.4.12 | Review | 24 | 2026-05-25 |
1.4.11 | Review | 74 | 2026-05-24 |
1.4.10 | Review | 74 | 2026-05-24 |
1.4.9 | Review | 74 | 2026-05-24 |
1.4.8 | Review | 74 | 2026-05-24 |
1.4.7 | Review | 74 | 2026-05-24 |
1.4.6 | Review | 74 | 2026-05-24 |
1.4.4 | Review | 74 | 2026-05-24 |
1.4.5 | Review | 74 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]