PkgRadar

npm · registry.npmjs.org

intl-tel-input

Remote Payload: matched "wget "

Why PkgRadar flagged 19.5.6

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/third_party/libphonenumber/java/script/download-junit-jars.sh
mediumRemote Dependency SpecdevDependencies.region-flags="https://github.com/fonttools/region-flags/archive/refs/tags/1.2.1.tar.gz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
19.5.6Review62026-06-13
19.5.5Review62026-06-13
29.1.0Low risk02026-06-13
19.5.7Review62026-06-13
29.0.5Low risk02026-06-05
29.0.4Low risk02026-05-30
29.0.3Low risk02026-05-28
29.0.1Low risk02026-05-28
29.0.2Low risk02026-05-28

Block this in CI

PkgRadar gates intl-tel-input (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]