PkgRadar

npm · registry.npmjs.org

@chorus-aidlc/chorus

Credential File Packaged: package/.next/standalone/.env

Why PkgRadar flagged 0.9.1

SeveritySignalEvidence
highCredential File Packagedpackage/.next/standalone/.env · package/.next/standalone/.env
mediumRemote Payloadmatched "curl " · package/.next/standalone/public/chorus-plugin/bin/chorus-api.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.1High risk522026-06-10
0.9.4High risk522026-06-10
0.9.3High risk522026-06-10
0.9.2High risk522026-06-10
0.8.2High risk522026-06-10
0.9.0High risk522026-06-10

Related campaigns

Block this in CI

PkgRadar gates @chorus-aidlc/chorus (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @chorus-aidlc/[email protected]
@chorus-aidlc/chorus — npm security scan | PkgRadar