PkgRadar

npm · registry.npmjs.org

tal-mathgpt-render

Remote Payload: matched "wget "

Why PkgRadar flagged 1.2.8-34

SeveritySignalEvidence
mediumRemote Payloadmatched "wget " · package/dist/bundle.cjs.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/bundle.cjs.js
mediumRemote Payloadmatched "wget " · package/dist/bundle.esm.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/bundle.esm.js
mediumRemote Payloadmatched "wget " · package/dist/bundle.umd.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/bundle.umd.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/vl.cjs.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/vl.esm.mjs
mediumLarge Javascript Payload6613605 bytes · package/dist/jyyAnswerFilled.cjs.js
mediumLarge Javascript Payload6613051 bytes · package/dist/jyyAnswerFilled.esm.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.2.8-36Low risk02026-06-04
1.2.8-34Review532026-05-26
1.2.8-35Review532026-05-26

Block this in CI

PkgRadar gates tal-mathgpt-render (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]