PkgRadar

npm · registry.npmjs.org

@kodax-ai/kodax

Credential file access: matched ".SSH"

Why PkgRadar flagged 0.7.42

SeveritySignalEvidence
highCredential file accessmatched ".SSH" · package/dist/chunks/chunk-ZZ4KRK2B.js
mediumRemote Payloadmatched "Invoke-WebRequest" · package/dist/chunks/chunk-7JLYVWAF.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunks/chunk-7JLYVWAF.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunks/chunk-KUX5LRPP.js
mediumRemote Payloadmatched "invoke-webrequest" · package/dist/chunks/chunk-ZZ4KRK2B.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunks/chunk-ZZ4KRK2B.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.48Low risk02026-06-11
0.7.47Low risk02026-06-10
0.7.46Low risk02026-06-07
0.7.45Low risk02026-06-01
0.7.44Low risk02026-05-29
0.7.42Review542026-05-25
0.7.43Review542026-05-25

Related campaigns

Block this in CI

PkgRadar gates @kodax-ai/kodax (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kodax-ai/[email protected]
@kodax-ai/kodax — npm security scan | PkgRadar