PkgRadar

npm · registry.npmjs.org

xyvcard-mall-diy

Remote Payload: matched "cUrl "

Why PkgRadar flagged 0.0.50

SeveritySignalEvidence
mediumRemote Payloadmatched "cUrl " · package/dist/components/vcard/vcard-goods-category/goods-category-view/index.js
mediumRemote Payloadmatched "cUrl " · package/dist/components/vcard/vcard-goods-hot/goods-hot-view/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.53Low risk02026-06-02
0.0.52Low risk02026-05-31
0.0.50Review242026-05-24
0.0.51Review242026-05-24

Block this in CI

PkgRadar gates xyvcard-mall-diy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
xyvcard-mall-diy — npm security scan | PkgRadar