PkgRadar

npm · registry.npmjs.org

node-libcurl

Native Addon Gyp Action: binding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle)

Why PkgRadar flagged 2.1.0

SeveritySignalEvidence
highNative Addon Gyp Actionbinding.gyp runs a script or chains shell during node-gyp build (executes outside package.json lifecycle) · package/binding.gyp

Scanned versions

VersionVerdictScoreScanned (UTC)
2.1.0High risk222026-06-10
2.1.0-5High risk222026-06-10
5.1.2High risk152026-06-10
5.1.1Review42026-06-06
5.0.2Review42026-05-31
5.1.0Review42026-05-31

Campaign attribution

Part of the Miasma worm campaign.

Block this in CI

PkgRadar gates node-libcurl (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]