PkgRadar

Package evidence

@maizzle/[email protected]

Remote Payload: matched "raw.githubusercontent.com"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@maizzle/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@maizzle/[email protected]"],"fail_on":"high"}'
Publishercossssmin
Artifact bytes567,756
Previous version6.0.0-rc.21
Published2026-05-22T13:43:29.177Z
SHA-256718d724e6275e5c7799942b0aeb74283503657c6068cc8106d561f51569a07f0

Why flagged

What the scanner saw

Remote Payload: matched "raw.githubusercontent.com"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
60Score
6.0.0-rc.22Version
Status history (1 event)
  1. newavailable · risk high · score 60 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

cossssmin

2 members · evidence strength 56

Evidence

Static findings

17 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/node_modules/giget/dist/_chunks/giget.mjsmatched "raw.githubusercontent.com"12
Show all 17 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumRemote Payloadpackage/node_modules/giget/dist/_chunks/giget.mjsmatched "raw.githubusercontent.com"12
lowObfuscationpackage/dist/render/createRenderer.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/transformers/entities.jsmatched "\\xA0"3
lowObfuscationpackage/node_modules/maizzle/node_modules/commander/lib/help.jsmatched "\\x1b"3
lowObfuscationpackage/node_modules/fast-string-truncated-width/dist/index.jsmatched "\\u001b"3
lowObfuscationpackage/node_modules/sisteransi/src/index.jsmatched "\\x1B"3
lowObfuscationpackage/node_modules/fast-wrap-ansi/lib/main.jsmatched "\\x1B"3
lowObfuscationpackage/node_modules/picocolors/picocolors.jsmatched "\\x1b"3
lowObfuscationpackage/dist/serve.jsmatched "\\x1b"3
lowObfuscationpackage/node_modules/fast-string-truncated-width/dist/utils.jsmatched "\\uD800"3
lowObfuscationpackage/node_modules/giget/dist/_chunks/libs/citty.mjsmatched "\\u001B"3
lowObfuscationpackage/node_modules/giget/dist/_chunks/giget.mjsmatched "\\x1B"3
lowObfuscationpackage/node_modules/@clack/core/dist/index.mjsmatched "\\u2588"3
lowObfuscationpackage/node_modules/@clack/prompts/dist/index.mjsmatched "\\u25C6"3
lowObfuscationpackage/node_modules/citty/dist/index.mjsmatched "\\u001B"3
lowObfuscationpackage/node_modules/maizzle/dist/commands/new.mjsmatched "\\x1b"3
lowObfuscationpackage/node_modules/giget/dist/_chunks/libs/tar.mjsmatched "\\x00"3

Manifest

Package metadata

Scripts7
  • buildtsdown
  • devvitest
  • lintoxlint
  • prepublishOnlynpm run build
  • pretestnpm run lint
  • releasenpm run build && npx np
  • testvitest run --coverage
Dependencies44
  • @maizzle/tailwindcsslatest
  • @tailwindcss/postcss^4.2.2
  • @tailwindcss/vite^4.2.2
  • @unhead/vue^3.0.4
  • @vitejs/plugin-vue^6.0.4
  • @vueuse/core^14.2.1
  • class-variance-authority^0.7.1
  • clsx^2.1.1
  • color-shorthand-hex-to-six-digit^5.1.3
  • css-select^7.0.0
  • culori^4.0.2
  • defu^6.1.4
  • dom-serializer^3.0.0
  • domhandler^6.0.1
  • email-comb^7.1.3
  • html-crush^6.1.3
  • htmlparser2^12.0.0
  • is-url-superb^6.1.0
  • jiti^2.6.1
  • juice^11.1.1
  • lucide-vue-next^1.0.0
  • maizzlelatest
  • markdown-exit^1.0.0-beta.9
  • nodemailer^8.0.5
  • ora^9.3.0
  • oxfmt^0.35.0
  • postcss^8.5.6
  • postcss-calc^10.1.1
  • postcss-merge-longhand^7.0.5
  • postcss-safe-parser^7.0.1
  • …and 14 more.