PkgRadar

npm · registry.npmjs.org

latchkey

Remote Payload: matched "curl "

Why PkgRadar flagged 2.12.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
2.16.1Low risk02026-06-16
2.16.0Low risk02026-06-10
2.15.4Low risk02026-06-09
2.15.3Low risk02026-06-09
2.15.2Low risk02026-06-09
2.15.1Low risk02026-06-04
2.15.0Low risk02026-06-01
2.14.0Low risk02026-05-29
2.13.0Low risk02026-05-29
2.12.2Low risk02026-05-28
2.12.1Review112026-05-27
2.11.3Review172026-05-25
2.12.0Review172026-05-25

Block this in CI

PkgRadar gates latchkey (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
latchkey — npm security scan | PkgRadar