PkgRadar

npm · registry.npmjs.org

@kya-os/mcp-i

Js Obfuscated Fetch Exec, Credential file access

Why PkgRadar flagged 1.10.0

SeveritySignalEvidence
highJs Obfuscated Fetch Execpackage/dist/runtime/adapter-nextjs.js

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.4-canary.1Review52026-06-22
1.10.0High risk272026-06-22
1.11.0High risk272026-06-22
1.9.0High risk272026-06-22

Block this in CI

PkgRadar gates @kya-os/mcp-i (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kya-os/[email protected]
@kya-os/mcp-i — npm security scan | PkgRadar