PkgRadar

npm · registry.npmjs.org

tako.sh

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.0.0-596139b

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/src-B0HkRC-e.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-fecb240Low risk02026-06-13
0.0.0-56be7e6Low risk02026-06-13
0.0.0-cecb306Low risk02026-06-13
0.0.0-de6bfffLow risk02026-06-13
0.0.0-f60cd55Low risk02026-06-12
0.0.0-0efbef9Low risk02026-06-11
0.0.0-b06e478Low risk02026-06-11
0.0.0-84ae4a7Low risk02026-06-11
0.0.0-ecccf76Low risk02026-06-09
0.0.0-8be1a30Low risk02026-06-09
0.0.0-a2b721cLow risk02026-06-06
0.0.0-958986fLow risk02026-06-04
0.0.0-7c7271cLow risk02026-06-03
0.0.0-23f2ed8Low risk02026-05-27
0.0.0-fd52ca1Low risk02026-05-25
0.0.0-596139bReview122026-05-25
0.0.0-657544bReview122026-05-25
0.0.0-29544d9Review122026-05-25
0.0.0-1744fcbReview122026-05-24
0.0.0-fbd7e9cReview122026-05-24
0.0.0-2a3b832Review122026-05-24

Block this in CI

PkgRadar gates tako.sh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]