PkgRadar

npm · registry.npmjs.org

mjs-eslint-helper

Credential File Packaged, Suspicious Publish Context

Early detection

PkgRadar flagged this 10h before public disclosure

Detected 2026-06-18 · disclosed as MAL-2026-6190 on 2026-06-19

Why PkgRadar flagged 4.0.1

SeveritySignalEvidence
mediumCredential File Packagedpackage/.env
mediumSuspicious Publish Context

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.1High risk252026-06-20

Block this in CI

PkgRadar gates mjs-eslint-helper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]