PkgRadar

npm · registry.npmjs.org

@smmachine/launcher

Credential File Packaged: package/apps/webapp/.next/standalone/apps/webapp/.env

Why PkgRadar flagged 0.3.0

SeveritySignalEvidence
highCredential File Packagedpackage/apps/webapp/.next/standalone/apps/webapp/.env · package/apps/webapp/.next/standalone/apps/webapp/.env
highCredential file accessmatched "github_token" · package/dist/index.cjs
highCredential file accessmatched "github_token" · package/dist/rest/main.cjs
highCredential file accessmatched "github_token" · package/apps/webapp/.next/server/chunks/ssr/[root-of-the-server]__0tdz~ex._.js
highCredential file accessmatched "github_token" · package/apps/webapp/.next/standalone/apps/webapp/.next/server/chunks/ssr/[root-of-the-server]__0tdz~ex._.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/rest/main.cjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/compiled/next-server/app-page-turbo-experimental.runtime.prod.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/compiled/next-server/app-page-turbo.runtime.prod.js
mediumRemote Payloadmatched "cUrl " · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/client/components/segment-cache/cache.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/compiled/comment-json/index.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/compiled/conf/index.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/apps/webapp/.next/standalone/node_modules/.pnpm/[email protected]_@[email protected][email protected][email protected][email protected][email protected]/node_modules/next/dist/compiled/conf/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.3.0Review1332026-05-24
0.4.0Review1332026-05-24

Related campaigns

Block this in CI

PkgRadar gates @smmachine/launcher (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @smmachine/[email protected]