PkgRadar

npm · registry.npmjs.org

lightswind

Remote Payload: matched "curl "

Why PkgRadar flagged 3.1.28

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/components/ui/smokey-cursor-hero.js
mediumRemote Payloadmatched "curl " · package/dist/src/components/ui/smokey-cursor-hero.js
mediumRemote Payloadmatched "curl " · package/dist/components/ui/smokey-cursor.js
mediumRemote Payloadmatched "curl " · package/dist/src/components/ui/smokey-cursor.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.1.27Low risk02026-06-15
3.1.30Low risk02026-06-15
3.1.28Review482026-05-25
3.1.29Review482026-05-25

Related campaigns

Block this in CI

PkgRadar gates lightswind (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]