PkgRadar

npm · registry.npmjs.org

gensparx

Remote Payload: matched "curl "

Why PkgRadar flagged 1.0.16-gensparx

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/onboard-skills-CcTjeegG.js
mediumRemote Payloadmatched "curl " · package/dist/onboard-skills-DNC4uuqX.js
mediumRemote Payloadmatched "cUrl " · package/dist/pi-embedded-helpers-Bwd1_tI5.js
mediumRemote Payloadmatched "cUrl " · package/dist/plugin-sdk/pi-embedded-helpers-CAFZh_OP.js
mediumRemote Payloadmatched "cUrl " · package/dist/plugin-sdk/pi-embedded-helpers-CMK_q1Z5.js
mediumRemote Payloadmatched "cUrl " · package/dist/pi-embedded-helpers-yOWw1sGr.js
mediumRemote Payloadmatched "cUrl " · package/dist/qr-cli-6x8wG9T0.js
mediumRemote Payloadmatched "cUrl " · package/dist/qr-cli-BCjRryWR.js
mediumRemote Payloadmatched "cUrl " · package/dist/sandbox-DX-H4kpF.js
mediumRemote Payloadmatched "cUrl " · package/dist/sandbox-gv66G0EY.js
mediumRemote Payloadmatched "curl " · package/skills/openai-whisper-api/scripts/transcribe.sh
mediumRemote Payloadmatched "cUrl " · package/extensions/voice-call/src/cli.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.16-gensparxReview2562026-05-25
2026.5.25Review2562026-05-25

Related campaigns

Block this in CI

PkgRadar gates gensparx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]