PkgRadar

npm · registry.npmjs.org

@lvce-editor/static-server

Credential file access: matched ".npmrc"

Why PkgRadar flagged 0.81.10

SeveritySignalEvidence
highCredential file accessmatched ".npmrc" · package/static/ec38d11/extensions/builtin.vscode-icons/icon-theme.json
mediumObfuscation Densityhigh encoded/escaped-token density · package/static/ec38d11/js/babel-parser.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/static/ec38d11/packages/chat-math-worker/dist/chatMathWorkerMain.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/static/ec38d11/packages/error-worker/dist/errorWorkerMain.js
mediumRemote Payloadmatched "cUrl " · package/static/ec38d11/packages/extension-host-worker/dist/extensionHostWorkerMain.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/static/ec38d11/packages/renderer-process/dist/rendererProcessMain.js
mediumRemote Payloadmatched "cURL\n " · package/static/ec38d11/packages/renderer-worker/dist/rendererWorkerMain.js
mediumRemote Payloadmatched "github.com/${repository}/releases/download" · package/static/ec38d11/packages/update-worker/dist/updateWorkerMain.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.83.1Low risk02026-06-03
0.83.0Low risk02026-06-02
0.82.7Low risk02026-05-31
0.82.6Low risk02026-05-29
0.82.5Low risk02026-05-29
0.82.4Low risk02026-05-29
0.82.2Low risk02026-05-29
0.82.3Low risk02026-05-29
0.82.1Low risk02026-05-28
0.81.15Low risk02026-05-28
0.82.0Low risk02026-05-28
0.81.14Low risk02026-05-27
0.81.13Low risk02026-05-26
0.81.12Low risk02026-05-25
0.81.10Review662026-05-24
0.81.11Review662026-05-24

Block this in CI

PkgRadar gates @lvce-editor/static-server (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @lvce-editor/[email protected]