PkgRadar

npm · registry.npmjs.org

@aooth/login-client

Suspicious Publish Context: {"package_age_days":6,"publisher":"mav-rik","burst_same_day":6,"burst_week":9,"lure":null,"version_anomaly":false}

Why PkgRadar flagged 0.1.20

SeveritySignalEvidence
mediumSuspicious Publish Context{"package_age_days":6,"publisher":"mav-rik","burst_same_day":6,"burst_week":9,"lure":null,"version_anomaly":false}

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.20Review102026-06-11
0.1.19Review102026-06-11
0.1.18Low risk02026-06-11
0.1.17Low risk02026-06-11
0.1.16Low risk02026-06-09
0.1.15Low risk02026-06-08
0.1.14Low risk02026-06-08
0.1.13Low risk02026-06-08
0.1.12Low risk02026-06-08
0.1.11Low risk02026-06-08
0.1.10Low risk02026-06-07
0.1.8Low risk02026-06-06
0.1.9Low risk02026-06-06

Block this in CI

PkgRadar gates @aooth/login-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @aooth/[email protected]