PkgRadar

npm · registry.npmjs.org

fbi-proxy

Remote Payload: matched "curl "

Why PkgRadar flagged 1.18.0

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/cli.js
mediumRemote Payloadmatched "curl " · package/ts/setup.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.18.0Review72026-06-01
1.16.0Review72026-06-01
1.17.0Review72026-06-01

Block this in CI

PkgRadar gates fbi-proxy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]