PkgRadar

npm · registry.npmjs.org

openfox

Remote Payload: matched "curl "

Why PkgRadar flagged 2.0.0-beta.4

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/pwa-76XP2DY2.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0-beta.4Review112026-06-16
2.0.0-beta.3Review112026-06-16
2.0.0-beta.2Review112026-06-15
2.0.0-beta.1Review172026-06-15
2.0.0-beta.0Review112026-06-14
1.6.103Review172026-06-12
1.6.102Review172026-06-12
1.6.101Review172026-06-10
1.6.100Review172026-06-10
1.6.99Review172026-06-09
1.6.98Review172026-06-09
1.6.97Review172026-06-09
1.6.96Review172026-06-08
1.6.95Review122026-06-08
1.6.94Review122026-06-07
1.6.93Review122026-05-27
1.6.92Review122026-05-27
1.6.90Review422026-05-24
1.6.91Review422026-05-24

Block this in CI

PkgRadar gates openfox (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]