PkgRadar

npm · registry.npmjs.org

kaijibot

Remote Payload: matched "curl "

Why PkgRadar flagged 2026.6.12-2

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/extensions/diffs/node_modules/playwright-core/bin/reinstall_chrome_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/dist/extensions/diffs/node_modules/playwright-core/bin/reinstall_chrome_stable_mac.sh
mediumRemote Payloadmatched "curl " · package/dist/extensions/diffs/node_modules/playwright-core/bin/reinstall_msedge_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/dist/extensions/diffs/node_modules/playwright-core/bin/reinstall_msedge_dev_mac.sh
mediumRemote Payloadmatched "curl " · package/dist/extensions/diffs/node_modules/playwright-core/bin/reinstall_msedge_stable_mac.sh
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-BjSokDjV.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.12-2High risk1052026-06-12
2026.6.12High risk732026-06-11
2026.6.11High risk1052026-06-11
2026.6.10High risk732026-06-10
2026.5.28High risk732026-06-10
2026.5.27High risk732026-06-10
2026.6.9High risk732026-06-10
2026.6.5High risk732026-06-10
2026.6.8High risk732026-06-10
2026.6.4High risk732026-06-10
2026.6.3-2High risk732026-06-10
2026.6.3-1High risk732026-06-10
2026.6.2-3High risk732026-06-10
2026.6.2-2High risk732026-06-10
2026.6.2-1High risk732026-06-10
2026.6.1-1High risk732026-06-10
2026.5.31-4High risk732026-06-10
2026.5.29High risk732026-06-10
2026.5.31-3Review732026-05-31
2026.5.31-2Review732026-05-31
2026.5.31-1Review732026-05-30
2026.5.30-7Review732026-05-30
2026.5.30-6Review352026-05-30
2026.5.26Review1052026-05-30
2026.5.30-5Review732026-05-30
2026.5.23Review732026-05-30
2026.5.24Review1052026-05-30
2026.5.25Review1052026-05-30
2026.5.30-4Review732026-05-30
2026.5.30-2Review732026-05-30
2026.5.30-3Review732026-05-30
2026.5.30Review732026-05-30

Block this in CI

PkgRadar gates kaijibot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]