npm · registry.npmjs.org
@ductape/sdk
Credential file access: matched ".AWS"
Why PkgRadar flagged 0.1.12
| Severity | Signal | Evidence |
|---|---|---|
| high | Credential file access | matched ".AWS" · package/dist/brokers/utils/broker.util.js |
| high | Credential file access | matched ".AWS" · package/dist/brokers/brokers.service.js |
| high | Credential file access | matched ".AWS" · package/dist/products/validators/joi-validators/create.productStorage.validator.js |
| high | Credential file access | matched ".AWS" · package/dist/products/utils/functions.utils.js |
| high | Credential file access | matched ".AWS" · package/dist/processor/services/processor.service.js |
| high | Credential file access | matched ".AWS" · package/dist/products/services/products.service.js |
| high | Credential file access | matched ".AWS" · package/dist/storage/storage-cloud-link.util.js |
| high | Credential file access | matched ".AWS" · package/dist/storage/storage.service.js |
| high | Credential file access | matched ".AWS" · package/dist/processor/utils/storage.util.js |
| high | Credential file access | matched ".AWS" · package/dist/storage/utils/storage.util.js |
| high | Credential file access | matched ".aws" · package/package.json |
| medium | Remote Payload | matched "cUrl " · package/dist/brokers/brokers.service.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.17 | Low risk | 0 | 2026-06-12 |
0.1.16 | Low risk | 0 | 2026-06-12 |
0.1.14 | Low risk | 0 | 2026-06-09 |
0.1.13 | Low risk | 0 | 2026-06-08 |
0.1.12 | Review | 92 | 2026-05-25 |
0.1.10 | Review | 92 | 2026-05-24 |
0.1.11 | Review | 92 | 2026-05-24 |
Related campaigns
- feekayo — 3 releases, max score 104
Block this in CI
pkgradar gate --ecosystem npm @ductape/[email protected]