PkgRadar

npm · registry.npmjs.org

@cafeai/cafe-code

Credential file access: matched ".SSH"

Why PkgRadar flagged 0.0.36

SeveritySignalEvidence
highCredential file accessmatched ".SSH" · package/dist/apps/desktop/dist-electron/main.cjs
highCredential file accessmatched ".ssh" · package/dist/apps/server/dist/client/assets/ssh-config-BgfXC-Er.js
highCredential file accessmatched ".ssh" · package/dist/client/assets/ssh-config-BgfXC-Er.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/apps/server/dist/client/assets/blade-DghGRsw7.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/client/assets/blade-DghGRsw7.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/apps/server/dist/client/assets/julia-CgTICk1r.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/client/assets/julia-CgTICk1r.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/apps/server/dist/client/assets/php-CSWOrrL9.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/client/assets/php-CSWOrrL9.js
mediumLarge Javascript Payload3081486 bytes · package/dist/apps/server/dist/client/assets/index-DfRZijch.js
mediumLarge Javascript Payload3081486 bytes · package/dist/client/assets/index-DfRZijch.js
mediumLarge Javascript Payload3211013 bytes · package/dist/apps/server/dist/bin.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.36Review1202026-05-25
0.0.35Review1202026-05-25
0.0.28Review1202026-05-24

Related campaigns

Block this in CI

PkgRadar gates @cafeai/cafe-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cafeai/[email protected]