PkgRadar

npm · registry.npmjs.org

@common-stack/generate-plugin

Credential file access: matched ".npmrc"

Early detection

PkgRadar flagged this 15.3 days before public disclosure

Detected 2026-05-26 · disclosed as MAL-2026-5546 on 2026-06-11

Why PkgRadar flagged 9.0.6-alpha.1

SeveritySignalEvidence
mediumCredential file accessmatched ".npmrc" · package/lib/utils/copyDotfiles.mjs
mediumCredential file accessmatched ".npmrc" · package/lib/generators/add-fullstack/updates/npmAuthSetup.mjs
mediumCredential file accessmatched ".npmrc" · package/src/utils/copyDotfiles.ts
mediumCredential file accessmatched ".npmrc" · package/src/generators/add-fullstack/updates/npmAuthSetup.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
9.0.6-alpha.1Review252026-06-08
9.0.6-alpha.0Review252026-06-08
10.0.1-alpha.0Review252026-06-04
9.0.5-alpha.5Review252026-06-04
9.0.5-alpha.4Review252026-06-04
9.0.5-alpha.3Review252026-06-04
9.0.5-alpha.1Review252026-06-04
9.0.5-alpha.2Review252026-06-04
9.0.5-alpha.0Review252026-06-04
9.0.4-alpha.5Review252026-06-01
9.0.4-alpha.4Review252026-05-29
9.0.4-alpha.3Review252026-05-28
9.0.4-alpha.2Review252026-05-28
9.0.4-alpha.1Review252026-05-27
9.0.4-alpha.0Review252026-05-26
9.0.2-alpha.24Review252026-05-26

Block this in CI

PkgRadar gates @common-stack/generate-plugin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @common-stack/[email protected]