PkgRadar

npm · registry.npmjs.org

protocol-proxy

Remote Payload: matched "curl "

Why PkgRadar flagged 3.3.17

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/lib/pure-agent/node_modules/better-sqlite3/deps/download.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.3.17Review122026-06-06
3.3.16Review122026-06-06
3.3.15Review82026-06-01
3.3.14Low risk02026-05-30
3.3.13Low risk02026-05-29
3.3.11Low risk02026-05-28
3.3.10Review122026-05-27
3.3.9Review82026-05-26
3.3.8Review82026-05-26
3.3.6Review82026-05-25
3.3.5Review82026-05-25
3.3.4Review122026-05-25
3.3.3Review742026-05-24
3.3.2Review742026-05-24
3.3.0Review742026-05-24
3.3.1Review742026-05-24

Block this in CI

PkgRadar gates protocol-proxy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]