PkgRadar

npm · registry.npmjs.org

safecheck-client

Remote Payload: matched "cUrl "

Why PkgRadar flagged 3.0.27-yuchuan-32

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/src/androidBase.js
mediumRemote Payloadmatched "cUrl\r\n" · package/src/main.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.0.27-yuchuan-36Low risk02026-06-09
3.0.16-zk-72-103Low risk02026-06-06
3.0.16-zk-72-102Low risk02026-06-06
3.0.16-zk-72-100Low risk02026-06-06
3.0.27-yuchuan-35Low risk02026-06-03
3.0.16-zk-72-99Low risk02026-06-03
3.0.16-zk-72-98Low risk02026-06-03
3.0.16-zk-72-97Low risk02026-06-02
3.0.27-yuchuan-34Low risk02026-06-02
3.0.16-zk-72-96Low risk02026-06-02
3.0.16-zk-72-95Low risk02026-06-02
3.0.25-als-93Low risk02026-06-02
3.0.16-zk-72-94Low risk02026-06-02
3.0.27-yuchuan-33Low risk02026-06-01
3.0.25-als-92Low risk02026-05-29
3.0.27-yuchuan-32Review242026-05-25

Block this in CI

PkgRadar gates safecheck-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]