PkgRadar

npm · registry.npmjs.org

create-walle

Remote Payload: matched "curl "

Why PkgRadar flagged 0.9.25

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/template/claude-task-manager/bin/restart-ctm.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.25Review272026-06-11
0.9.24Review272026-06-11
0.9.20Review342026-06-11
0.9.21Review342026-06-11
0.9.22Review342026-06-11
0.9.23Review272026-06-11

Block this in CI

PkgRadar gates create-walle (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]