PkgRadar

npm · registry.npmjs.org

needle-cloud

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 2.3.5-next.1781559918.frantic-julius-caesar.2611565

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/cli-89e6b3db.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.5-next.1781559918.frantic-julius-caesar.2611565Review32026-06-15
2.3.5Review32026-06-12
2.3.4Review32026-06-12
2.3.3Review32026-06-12
2.3.2Review32026-06-10
2.3.1-rc.1781099147.824848fReview32026-06-10
2.3.1Review32026-06-10
2.3.0-rc.1781095139.e7b64acReview32026-06-10
2.3.0Review32026-06-10
2.3.0-rc.1780351047.a96f5abReview32026-06-01
2.3.0-rc.1780338677.c02f46bReview32026-06-01
2.3.0-rc.1780338373.1807fa9Review32026-06-01
2.3.0-alpha.6Review32026-05-30
2.3.0-alpha.5Review32026-05-30
2.3.0-alpha.3Review32026-05-29
2.3.0-alpha.4Review32026-05-29
2.3.0-alpha.1Review32026-05-27
2.3.0-alpha.2Review32026-05-27

Block this in CI

PkgRadar gates needle-cloud (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]