PkgRadar

npm · registry.npmjs.org

@easbot/tui

Credential file access: matched ".SSH"

Why PkgRadar flagged 0.2.19

SeveritySignalEvidence
highCredential file accessmatched ".SSH" · package/dist/index.cjs
highCredential file accessmatched ".SSH" · package/dist/index.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.cjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.41Low risk02026-06-13
0.2.40Low risk02026-06-12
0.2.39Low risk02026-06-11
0.2.38Low risk02026-06-11
0.2.37Low risk02026-06-11
0.2.36Low risk02026-06-10
0.2.35Low risk02026-06-10
0.2.34Low risk02026-06-09
0.2.33Low risk02026-06-07
0.2.32Low risk02026-06-04
0.2.30Low risk02026-06-03
0.2.28Low risk02026-06-03
0.2.27Low risk02026-06-02
0.2.26Low risk02026-05-31
0.2.25Low risk02026-05-30
0.2.24Low risk02026-05-30
0.2.23Low risk02026-05-27
0.2.22Low risk02026-05-26
0.2.21Low risk02026-05-25
0.2.19Review502026-05-24
0.2.20Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates @easbot/tui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @easbot/[email protected]