Go modules · proxy.golang.org
github.com/lotus-web3/ribs
Shell Credential File Read, Remote Payload, Obfuscation Density
Why PkgRadar flagged v0.0.0-20241122101807-492cc90f806e
| Severity | Signal | Evidence |
|---|---|---|
| high | Shell Credential File Read | — |
| medium | Remote Payload | — |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v0.0.0-20241122101807-492cc90f806e | High risk | 57 | 2026-06-28 |
v0.0.0-20241121163450-d9d0b4fc7cd0 | High risk | 57 | 2026-06-28 |
v0.0.0-20241121011637-c1880000cd74 | High risk | 57 | 2026-06-28 |
v0.0.0-20250411134606-7fc60cc55166 | High risk | 57 | 2026-06-28 |
v0.0.0-20250411144720-0626b094116a | High risk | 57 | 2026-06-28 |
v0.0.0-20250429220245-c20af97cdbc9 | High risk | 45 | 2026-06-28 |
v0.0.0-20241004072849-acc7ed22cbb7 | High risk | 57 | 2026-06-28 |
Block this in CI
pkgradar gate --ecosystem go github.com/lotus-web3/[email protected]