PkgRadar

Package evidence

@uipath/[email protected]

Remote Payload: matched "Curl "

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
64
Versions published
2
First published
May 2026
Publisher
vnaren23

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@uipath/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@uipath/[email protected]"],"fail_on":"review"}'
Publishervnaren23
Artifact bytes47,243,811
Previous version1.0.0-beta.1
Published2026-05-25T09:17:07.707Z
SHA-256355cb03bf9c825d9e97fe22d0b616d0dfbd53c48e7fe3b17f145b921f4b1821f

Why flagged

What the scanner saw

Remote Payload: matched "Curl "

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
172Score
1.0.0-beta.2Version
Status history (1 event)
  1. newavailable · risk review · score 172 · status changed

Evidence

Static findings

245 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/chunk-7HG3KS7V.jsmatched "Curl "12
mediumObfuscation Densitypackage/chunk-7LF7TUYR.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-AV2XMJZK.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-DP4VB7EI.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-JA4SO6QN.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-LE344D6P.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-OCJB2TQU.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-Q3TZ5E3J.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-QSPXPEUM.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-RQKBBL3R.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-X3MDAFQV.jshigh encoded/escaped-token density12
mediumLarge Javascript Payloadpackage/chunk-5LGMGLPM.js2628024 bytes10
Show all 245 findings (low-signal and informational)

Showing 60 of 245 findings.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/chunk-7HG3KS7V.jsmatched "Curl "12
mediumObfuscation Densitypackage/chunk-7LF7TUYR.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-AV2XMJZK.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-DP4VB7EI.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-JA4SO6QN.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-LE344D6P.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-OCJB2TQU.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-Q3TZ5E3J.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-QSPXPEUM.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-RQKBBL3R.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/chunk-X3MDAFQV.jshigh encoded/escaped-token density12
mediumLarge Javascript Payloadpackage/chunk-5LGMGLPM.js2628024 bytes10
lowObfuscationpackage/chunk-22FB6FDO.jsmatched "\\xE9"3
lowObfuscationpackage/chunk-26HBXFOF.jsmatched "\\xED"3
lowObfuscationpackage/chunk-2OT5DL67.jsmatched "\\u016D"3
lowObfuscationpackage/chunk-35P35R4B.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-35SAPIPO.jsmatched "\\xED"3
lowObfuscationpackage/chunk-35UVHQNZ.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-3CXBWJMK.jsmatched "\\xF6"3
lowObfuscationpackage/chunk-3JRA4PLP.jsmatched "\\xE4"3
lowObfuscationpackage/chunk-44Y6LCGU.jsmatched "\\xFC"3
lowObfuscationpackage/chunk-4DL5ZETN.jsmatched "\\u0275"3
lowObfuscationpackage/chunk-4EEYDUIP.jsmatched "\\u014D"3
lowObfuscationpackage/chunk-4EVFFVML.jsmatched "\\xFD"3
lowObfuscationpackage/chunk-4N3AI4FW.jsmatched "\\u017D"3
lowObfuscationpackage/chunk-4RC3DPEI.jsmatched "\\u0275"3
lowObfuscationpackage/chunk-4V2KJNDT.jsmatched "\\xFC"3
lowObfuscationpackage/chunk-5273O2DN.jsmatched "\\xCE"3
lowObfuscationpackage/chunk-5BQKAR6A.jsmatched "\\xE7"3
lowObfuscationpackage/chunk-5MT5VRIU.jsmatched "\\xE3"3
lowObfuscationpackage/chunk-5ORJAWGA.jsmatched "\\xF4"3
lowObfuscationpackage/chunk-5ORQKHAE.jsmatched "\\xE5"3
lowObfuscationpackage/chunk-5YPRY6TZ.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-64N3X35N.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-67OCW6FB.jsmatched "\\xE5"3
lowObfuscationpackage/chunk-6AEFIYR5.jsmatched "\\u0275"3
lowObfuscationpackage/chunk-6MB4C432.jsmatched "\\u010D"3
lowObfuscationpackage/chunk-6NRLHSPV.jsmatched "\\xE9"3
lowObfuscationpackage/chunk-6PRA22X5.jsmatched "\\xE1"3
lowObfuscationpackage/chunk-6TRN24WM.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-6XPGXWNC.jsmatched "\\u0101"3
lowObfuscationpackage/chunk-6YDBCCFI.jsmatched "\\xEB"3
lowObfuscationpackage/chunk-73XD4VKN.jsmatched "\\u0101"3
lowObfuscationpackage/chunk-76JEL4MT.jsmatched "\\xE4"3
lowObfuscationpackage/chunk-7EQRZSTI.jsmatched "\\xE8"3
lowObfuscationpackage/chunk-7FN55G7Q.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-7GO2RJNZ.jsmatched "\\u016D"3
lowObfuscationpackage/chunk-7HG3KS7V.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-7LF7TUYR.jsmatched "\\u01B0"3
lowObfuscationpackage/chunk-7XMORYEY.jsmatched "\\u0275"3
lowObfuscationpackage/chunk-AE2CAJJW.jsmatched "\\u0259"3
lowObfuscationpackage/chunk-AEGGUDJL.jsmatched "\\xF4"3
lowObfuscationpackage/chunk-AEHI5GGR.jsmatched "\\u1E29"3
lowObfuscationpackage/chunk-ALRAVU4V.jsmatched "\\xF4"3
lowObfuscationpackage/chunk-AO6PUCC2.jsmatched "\\xE8"3
lowObfuscationpackage/chunk-AOEYLDSC.jsmatched "\\u2019"3
lowObfuscationpackage/chunk-AV2XMJZK.jsmatched "\\u0E19"3
lowObfuscationpackage/chunk-AWSJJEP7.jsmatched "\\u0101"3
lowObfuscationpackage/chunk-B3JIB7CB.jsmatched "\\xE4"3
lowObfuscationpackage/chunk-B433VOZ4.jsmatched "\\xE9"3