PkgRadar

npm · registry.npmjs.org

altair-static

Credential file access: matched ".AWS"

Why PkgRadar flagged 8.5.3

SeveritySignalEvidence
highCredential file accessmatched ".AWS" · package/build/dist/chunk-7THP26YK.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/build/dist/chunk-2OVBIND4.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/build/dist/chunk-74A26AAT.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/build/dist/chunk-CPMWLSLU.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/build/dist/chunk-GZBCODHK.js
mediumRemote Payloadmatched "curl " · package/build/dist/chunk-OG54YGKQ.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/build/index.js
mediumRemote Payloadmatched "cURL " · package/build/dist/assets/i18n/af-ZA.json
mediumRemote Payloadmatched "cURL " · package/build/dist/assets/i18n/ar-SA.json
mediumRemote Payloadmatched "cURL " · package/build/dist/assets/i18n/ca-ES.json
mediumRemote Payloadmatched "cURL " · package/build/dist/assets/i18n/cs-CZ.json
mediumRemote Payloadmatched "cURL " · package/build/dist/assets/i18n/da-DK.json

Scanned versions

VersionVerdictScoreScanned (UTC)
8.5.8-alpha.d658484.0Low risk02026-06-06
8.5.7Low risk02026-06-06
8.5.8-alpha.69d1042.0Low risk02026-06-06
8.5.7-alpha.3025f1c.0Low risk02026-06-06
8.5.7-alpha.1edee7e.0Low risk02026-06-06
8.5.6Low risk02026-06-06
8.5.6-alpha.ae4b3e4.0Low risk02026-06-06
8.5.6-alpha.7af8728.0Low risk02026-06-06
8.5.5Low risk02026-06-04
8.5.6-alpha.cddec71.0Low risk02026-06-04
8.5.4Low risk02026-06-03
8.5.5-alpha.e317be6.0Low risk02026-06-03
8.5.4-alpha.e5f673c.0Low risk02026-06-03
8.5.3Review1142026-05-24
8.5.4-alpha.8244b5b.0Review1142026-05-24
8.5.3-alpha.430ede9.0Review1142026-05-24
8.5.3-alpha.73edbb9.0Review1142026-05-24

Block this in CI

PkgRadar gates altair-static (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]