npm · registry.npmjs.org
tal-mathgpt-render
Remote Payload: matched "wget "
Why PkgRadar flagged 1.2.8-34
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "wget " · package/dist/bundle.cjs.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/bundle.cjs.js |
| medium | Remote Payload | matched "wget " · package/dist/bundle.esm.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/bundle.esm.js |
| medium | Remote Payload | matched "wget " · package/dist/bundle.umd.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/bundle.umd.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/vl.cjs.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/vl.esm.mjs |
| medium | Large Javascript Payload | 6613605 bytes · package/dist/jyyAnswerFilled.cjs.js |
| medium | Large Javascript Payload | 6613051 bytes · package/dist/jyyAnswerFilled.esm.mjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.2.8-36 | Low risk | 0 | 2026-06-04 |
1.2.8-34 | Review | 53 | 2026-05-26 |
1.2.8-35 | Review | 53 | 2026-05-26 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]