PkgRadar

npm · registry.npmjs.org

qcobjects

Remote Payload: matched "curl "

Why PkgRadar flagged 2.5.139-beta

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/bin/install/ubuntu18/gitlab-runner-installer.sh
mediumRemote Payloadmatched "curl " · package/install_qcobjects_macOS.sh
mediumRemote Payloadmatched "curl " · package/install_qcobjects_raspbian9.sh
mediumRemote Payloadmatched "curl " · package/install_qcobjects_rhel8.sh
mediumRemote Payloadmatched "wget " · package/install_qcobjects_ubuntu18x.sh
mediumRemote Payloadmatched "curl " · package/bin/install/macOS/install_qcobjects.sh
mediumRemote Payloadmatched "curl " · package/bin/install/raspberrypi_raspbian9/install_qcobjects.sh
mediumRemote Payloadmatched "curl " · package/bin/install/rhel8/install_qcobjects.sh
mediumRemote Payloadmatched "curl " · package/bin/install/ubuntu18/install_qcobjects.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
2.5.139-betaReview242026-06-12
2.5.140-betaReview242026-06-12
2.5.141-betaReview242026-06-12
2.5.142-betaReview242026-06-12

Block this in CI

PkgRadar gates qcobjects (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
qcobjects — npm security scan | PkgRadar