PkgRadar

npm · registry.npmjs.org

superlocalmemory

Remote Payload: matched "curl "

Why PkgRadar flagged 3.5.6

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/ide/hooks/tool-event-hook.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
3.5.6Review172026-06-02
3.5.7Review112026-06-02
3.5.5Review112026-05-31
3.5.4Review112026-05-31
3.5.2Review112026-05-31
3.5.1Review112026-05-31
3.5.0Review112026-05-31
3.4.64Review112026-05-31
3.4.62Review112026-05-31
3.4.63Review112026-05-31
3.4.61Review112026-05-31
3.4.60Review112026-05-30
3.4.59Review112026-05-30
3.4.58Review112026-05-30
3.4.56Review112026-05-30
3.4.55Review172026-05-30

Block this in CI

PkgRadar gates superlocalmemory (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]