PkgRadar

npm · registry.npmjs.org

@askjo/camofox-browser

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 1.11.1

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/scripts/postinstall.js
highInstall-time lifecycle scriptpostinstall="node scripts/postinstall.js" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node scripts/postinstall.js" · package.json
mediumRemote Payloadmatched "curl " · package/plugins/youtube/post-install.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.11.1Review772026-05-24
1.11.2Review772026-05-24

Block this in CI

PkgRadar gates @askjo/camofox-browser (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @askjo/[email protected]