PkgRadar

npm · registry.npmjs.org

nlm-memory

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.12.0

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/cli/digest.js
mediumRemote Payloadmatched "curl " · package/dist/install/ollama.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.12.0Review82026-06-11
0.11.1Review82026-06-10
0.11.0Review82026-06-10
0.10.1Review82026-06-10
0.10.0Review292026-06-10
0.9.2Review202026-06-10
0.9.1Review202026-06-10
0.9.0Review202026-06-10
0.8.0Review202026-06-10
0.7.0Review202026-06-10
0.6.0Review202026-06-10
0.5.22Review202026-06-08
0.5.21Review292026-06-02
0.5.20Review292026-06-02
0.5.19Review202026-06-02
0.5.18Review202026-05-30
0.5.17Review202026-05-30
0.5.16Review202026-05-30
0.5.15Review202026-05-30
0.5.14Review202026-05-30
0.5.13Review292026-05-30
0.5.12Review202026-05-30
0.5.11Review292026-05-30
0.5.10Review202026-05-30
0.5.9Review202026-05-30
0.5.8Review202026-05-30
0.5.7Review202026-05-30
0.5.5Review292026-05-29
0.5.6Review292026-05-29
0.5.0Review242026-05-29
0.4.1Review242026-05-29
0.4.2Review242026-05-29
0.4.0Review242026-05-29

Block this in CI

PkgRadar gates nlm-memory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]