PkgRadar

npm · registry.npmjs.org

total-recall-brain

Remote Payload: matched "curl "

Why PkgRadar flagged 3.6.9

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · package/src/cli/deploy.mjs
mediumCredential file accessmatched ".ssh/" · package/src/cli/deploy.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
3.6.9Review272026-06-13
3.6.8Review182026-06-12
3.6.7Review272026-06-12
3.6.6Review182026-06-09
3.6.5Review182026-06-05
3.6.3Review272026-06-02
3.6.4Review272026-06-02
3.5.0Review272026-06-02
3.4.0Review272026-06-02
3.3.0Review272026-05-30
3.2.3Review272026-05-30
3.2.2Review272026-05-30
3.2.1Review272026-05-30
3.1.2Review272026-05-29
3.1.1Review272026-05-29
3.1.0Review272026-05-29

Block this in CI

PkgRadar gates total-recall-brain (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]