PkgRadar

npm · registry.npmjs.org

@apralabs/apra-fleet

Js Hidden Powershell, Remote Payload, Credential file access

Why PkgRadar flagged 0.2.2

SeveritySignalEvidence
highJs Hidden Powershellpackage/dist/providers/agy.js
highJs Hidden Powershellpackage/dist/providers/claude.js
mediumRemote Payloadpackage/dist/services/vcs/azure-devops.js
mediumRemote Payloadpackage/dist/services/vcs/bitbucket.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.2Review892026-06-26
0.3.0Review892026-06-26

Block this in CI

PkgRadar gates @apralabs/apra-fleet (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @apralabs/[email protected]