PkgRadar

npm · registry.npmjs.org

groove-dev

Remote Payload: matched "curl "

Why PkgRadar flagged 0.27.172

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/node_modules/@groove-dev/daemon/src/llama-server.js
mediumRemote Payloadmatched "curl " · package/packages/daemon/src/llama-server.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/node_modules/@groove-dev/daemon/src/gateways/telegram.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/packages/daemon/src/gateways/telegram.js
mediumRemote Payloadmatched "curl " · package/node_modules/better-sqlite3/deps/download.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.27.172Review532026-05-30
0.27.171Review532026-05-30
0.27.168Review532026-05-28
0.27.169Review532026-05-28

Block this in CI

PkgRadar gates groove-dev (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]