PkgRadar

npm · registry.npmjs.org

forgecad

Remote Payload: matched "curl "

Why PkgRadar flagged 0.9.9

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/examples/mechanical/5-finger-robot-hand.forge.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/assets/DocsPage-9U1hGjrg.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/assets/index-CnZUgvOr.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/assets/index-DPSc7OlC.js
mediumLarge Javascript Payload13328897 bytes · package/dist/assets/evalWorker-CtO7GsJR.js
mediumLarge Javascript Payload4490869 bytes · package/dist-cli/forgecad.js
mediumLarge Javascript Payload13585136 bytes · package/dist/assets/reportWorker-Bz9tGiHb.js
mediumLarge Javascript Payload14992964 bytes · package/dist/assets/scalar-sampling-budget-Bmewod18.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.10.2Low risk02026-06-12
0.10.1Low risk02026-06-11
0.9.16Low risk02026-06-10
0.10.0Low risk02026-06-10
0.9.15Low risk02026-06-05
0.9.14Low risk02026-05-31
0.9.13Low risk02026-05-29
0.9.9Review402026-05-24
0.9.10Review402026-05-24

Related campaigns

Block this in CI

PkgRadar gates forgecad (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]