PkgRadar

npm · registry.npmjs.org

releasebird-javascript-sdk

Remote Payload: matched "curl "

Why PkgRadar flagged 1.0.96

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/backend-image-service/deploy-to-eb.sh
mediumRemote Payloadmatched "curl " · package/backend-image-service/quick-deploy.sh
mediumRemote Payloadmatched "curl " · package/backend-image-service/test-image.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.96Review182026-06-09
1.0.92Review362026-06-09
1.0.93Review362026-06-09
1.0.94Review362026-06-09
1.0.95Review182026-06-09

Block this in CI

PkgRadar gates releasebird-javascript-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]