PkgRadar

npm · registry.npmjs.org

tako-cli

Remote Payload: matched "curl "

Why PkgRadar flagged 0.3.1

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/dist/index.js
mediumCredential file accessmatched ".ssh/" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.1Review222026-06-11
0.2.60Review222026-06-11
0.2.9Low risk02026-06-11
0.2.10Low risk02026-06-11
0.2.11Low risk02026-06-11
0.2.61Low risk02026-06-11
0.2.59Low risk02026-05-29
0.2.57Low risk02026-05-28
0.2.58Low risk02026-05-28

Block this in CI

PkgRadar gates tako-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]