PkgRadar

npm · registry.npmjs.org

@nossen/qflush

Credential file access: matched "aws_access_key"

Why PkgRadar flagged 2.0.0

SeveritySignalEvidence
highCredential file accessmatched "aws_access_key" · package/dist/spyder/decoders/secrets-local.js
mediumRemote Payloadmatched "cUrl " · package/dist/commands/start.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.0Review422026-05-25
2.0.1Review422026-05-25

Related campaigns

Block this in CI

PkgRadar gates @nossen/qflush (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @nossen/[email protected]