PkgRadar

npm · registry.npmjs.org

svf-tools

Remote Payload: matched "github.com/bjjwwang/SVF-LLVM/releases/download"

Why PkgRadar flagged 1.0.1273

SeveritySignalEvidence
mediumRemote Payloadmatched "github.com/bjjwwang/SVF-LLVM/releases/download" · package/build.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.1273Review52026-06-08
1.0.1272Review52026-06-08
1.0.1271Review52026-06-08
1.0.1270Review52026-06-08
1.0.1269Review52026-06-08
1.0.1267Review52026-06-02
1.0.1268Review52026-06-02
1.0.1266Review52026-06-02
1.0.1265Review52026-06-02
1.0.1263Review52026-06-01
1.0.1264Review52026-06-01

Block this in CI

PkgRadar gates svf-tools (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]