PkgRadar

npm · registry.npmjs.org

@dvai-bridge/android-llama-core

Known Indicator Filename: package/android/src/main/cpp/native/llama.cpp/tools/server/public/bundle.js

Why PkgRadar flagged 4.0.0

SeveritySignalEvidence
highKnown Indicator Filenamepackage/android/src/main/cpp/native/llama.cpp/tools/server/public/bundle.js · package/android/src/main/cpp/native/llama.cpp/tools/server/public/bundle.js
highCredential file accessmatched "GITHUB_TOKEN" · package/android/src/main/cpp/native/llama.cpp/.github/workflows/ai-issues.yml
highCredential file accessmatched "github_token" · package/android/src/main/cpp/native/llama.cpp/.github/workflows/close-issue.yml
highCredential file accessmatched "github_token" · package/android/src/main/cpp/native/llama.cpp/.github/workflows/docker.yml
highCredential file accessmatched "github_token" · package/android/src/main/cpp/native/llama.cpp/.github/workflows/release.yml
highCredential file accessmatched "GITHUB_TOKEN" · package/android/src/main/cpp/native/llama.cpp/.github/workflows/winget.yml
mediumObfuscation Densityhigh encoded/escaped-token density · package/android/src/main/cpp/native/llama.cpp/tools/server/webui/package-lock.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/android/src/main/cpp/native/llama.cpp/scripts/compare-logprobs.py
mediumObfuscation Densityhigh encoded/escaped-token density · package/android/src/main/cpp/native/llama.cpp/gguf-py/gguf/quants.py
mediumRemote Payloadmatched "curl " · package/android/src/main/cpp/native/llama.cpp/scripts/snapdragon/qdc/tests/run_bench_tests_posix.py
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/android/src/main/cpp/native/llama.cpp/scripts/sync_vendor.py
mediumRemote Payloadmatched "wget\r\n\r\n\r\n" · package/android/src/main/cpp/native/llama.cpp/tools/server/tests/utils.py

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.2Low risk02026-05-28
4.0.0Review2552026-05-24
4.0.1Low risk02026-05-24

Block this in CI

PkgRadar gates @dvai-bridge/android-llama-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dvai-bridge/[email protected]