PkgRadar

npm · registry.npmjs.org

gxd-vue-library

Remote Payload: matched "cUrl "

Why PkgRadar flagged 1.1.248

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/build/template/coder/serve.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/src/dome/base/dynamic/setting.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.252Low risk02026-06-08
1.1.251Low risk02026-06-01
1.1.250Low risk02026-05-26
1.1.250-beta1Low risk02026-05-26
1.1.248Review122026-05-24
1.1.249Review122026-05-24

Block this in CI

PkgRadar gates gxd-vue-library (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]