PkgRadar

npm · registry.npmjs.org

zixulu

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 1.81.3

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/utils/downloadFromWinget.ts
mediumCredential file accessmatched ".npmrc" · package/dist/index.js
mediumCredential file accessmatched ".npmrc" · package/src/utils/pnpm.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
1.81.3Review162026-06-10
1.81.2Review162026-06-10
1.81.0Review162026-05-27
1.81.1Review162026-05-27
1.80.7Review162026-05-26
1.80.8Review162026-05-26

Block this in CI

PkgRadar gates zixulu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]