PkgRadar

npm · registry.npmjs.org

internallib_v557

Credential file access: matched ".npmrc"

Why PkgRadar flagged 1.0.24

SeveritySignalEvidence
highCredential file accessmatched ".npmrc" · package/index.js
mediumRemote Payloadmatched "curl " · package/index.js
mediumSuspicious Publish Context{"package_age_days":0,"publisher":"raptor_rex","burst_same_day":3,"burst_week":3,"lure":null,"version_anomaly":false}

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.24Review522026-06-11
1.0.23Review522026-06-11
1.0.22Review522026-06-11
1.0.21Review102026-06-11
1.0.20Review222026-06-11
1.0.19Review522026-06-11
1.0.18Review102026-06-11
1.0.17Review102026-06-11
1.0.15Review102026-06-11
1.0.16Review522026-06-11
1.0.14Review102026-06-11
1.0.12Review102026-06-11
1.0.13Review102026-06-11
1.0.11Review102026-06-11
1.0.10Review102026-06-11
1.0.9Review102026-06-11
1.0.8Review102026-06-11
1.0.6Review102026-06-11
1.0.7Review102026-06-11
1.0.5Review402026-06-11
1.0.4Review222026-06-11
1.0.3Review222026-06-11
1.0.2Review222026-06-11
1.0.1Review222026-06-11

Block this in CI

PkgRadar gates internallib_v557 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]