PkgRadar

npm · registry.npmjs.org

dev-env-bootstrapper

Credential file access: matched ".ssh"

Why PkgRadar flagged 1.5.2

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/lib/scanner-core.js
highCredential file accessmatched "github_token" · package/lib/trap-core.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/lib/trap-core.js
highInstall-time lifecycle scriptpostinstall="node lib/setup.js" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node lib/setup.js" · package.json
mediumRemote Payloadmatched "webhook.site" · package/lib/scanner-core.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/trap-core.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.1-securityLow risk02026-05-24
1.5.2High risk1492026-05-24
1.4.0High risk1492026-05-24
1.5.0High risk1492026-05-24

Related campaigns

Block this in CI

PkgRadar gates dev-env-bootstrapper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]