PkgRadar

npm · registry.npmjs.org

mppx

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.6.27

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/cli/cli.js
mediumRemote Payloadmatched "cUrl " · package/dist/viem/Client.js
mediumRemote Payloadmatched "cUrl " · package/dist/tempo/internal/defaults.js
mediumRemote Payloadmatched "cUrl " · package/dist/cli/plugins/tempo.js
mediumRemote Payloadmatched "cUrl " · package/dist/cli/utils.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/cli/utils.js
mediumRemote Payloadmatched "cUrl " · package/src/cli/cli.test.ts
mediumRemote Payloadmatched "cUrl " · package/src/cli/cli.ts
mediumRemote Payloadmatched "cUrl " · package/src/viem/Client.test.ts
mediumRemote Payloadmatched "cUrl " · package/src/viem/Client.ts
mediumRemote Payloadmatched "cUrl " · package/src/tempo/internal/defaults.ts
mediumRemote Payloadmatched "cUrl " · package/src/client/internal/Fetch.test.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0Low risk02026-06-11
0.6.31Low risk02026-06-11
0.6.30Low risk02026-06-04
0.6.29Low risk02026-06-02
0.6.27Review502026-05-24
0.6.28Review502026-05-24

Block this in CI

PkgRadar gates mppx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]