PkgRadar

npm · registry.npmjs.org

eslint-helper-1

Credential File Packaged: package/.env

Early detection

PkgRadar flagged this 7h before public disclosure

Detected 2026-06-18 · disclosed as MAL-2026-6188 on 2026-06-19

Why PkgRadar flagged 5.0.4

SeveritySignalEvidence
highCredential File Packagedpackage/.env · package/.env
mediumSuspicious Publish Context{"package_age_days":2,"publisher":"polyx","burst_same_day":4,"burst_week":10,"lure":{"kind":"token_affix","target":"eslint"},"version_anomaly":true,"new_account":false}

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.4High risk452026-06-20

Block this in CI

PkgRadar gates eslint-helper-1 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]