npm · registry.npmjs.org
traderclaw-cli
Remote Payload: matched "curl "
Why PkgRadar flagged 1.0.147
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "curl " · package/bin/installer-step-engine.mjs |
| medium | Remote Payload | matched "curl " · package/bin/openclaw-trader.mjs |
| medium | Remote Payload | matched "curl " · package/bin/cli.ts |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.147 | Review | 36 | 2026-05-24 |
1.0.148 | Review | 36 | 2026-05-24 |
Related campaigns
- david021943 — 2 releases, max score 49
Block this in CI
pkgradar gate --ecosystem npm [email protected]