PkgRadar

npm · registry.npmjs.org

pontx

Remote Payload: matched "cURL "

Why PkgRadar flagged 1.0.0-beta.8

SeveritySignalEvidence
mediumRemote Payloadmatched "cURL " · package/cjs/completion2.cjs
mediumRemote Payloadmatched "cURL " · package/cjs/run-cli.cjs
mediumRemote Payloadmatched "cURL " · package/cjs/spec-commands.cjs
mediumRemote Payloadmatched "cURL " · package/lib/builtin/apiExecutor.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/lib/builtin/check.test.js
mediumRemote Payloadmatched "cURL " · package/lib/cli/completion/providers/param.js
mediumRemote Payloadmatched "cURL " · package/lib/completion/providers/param.js
mediumRemote Payloadmatched "cURL " · package/lib/cli/spec-commands.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-beta.8Review502026-05-25
1.0.0-beta.9Review502026-05-25

Related campaigns

Block this in CI

PkgRadar gates pontx (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]