PkgRadar

PyPI · pypi.org

memsearch

Remote Payload: matched "curl "

Why PkgRadar flagged 0.4.10

SeveritySignalEvidence
mediumRemote Payloadmatched "curl " · memsearch-0.4.10/plugins/claude-code/hooks/session-start.sh
mediumRemote Payloadmatched "curl " · memsearch-0.4.10/plugins/codex/hooks/session-start.sh
mediumRemote Payloadmatched "curl " · memsearch-0.4.10/plugins/openclaw/install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.10High risk362026-06-16
0.4.9High risk362026-06-16
0.4.8High risk362026-06-15
0.4.7High risk362026-06-12
0.4.6Review362026-05-29
0.4.5Review362026-05-28

Block this in CI

PkgRadar gates memsearch (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi memsearch==0.4.10