PkgRadar

npm · registry.npmjs.org

new-ts-helper

Credential File Packaged: package/.env

Early detection

PkgRadar flagged this 3h before public disclosure

Detected 2026-06-19 · disclosed as MAL-2026-6227 on 2026-06-19

Why PkgRadar flagged 9.0.2

SeveritySignalEvidence
highCredential File Packagedpackage/.env · package/.env
mediumSuspicious Publish Context{"package_age_days":1,"publisher":"polyx","burst_same_day":4,"burst_week":10,"lure":null,"version_anomaly":true,"new_account":false}

Scanned versions

VersionVerdictScoreScanned (UTC)
9.0.2High risk452026-06-20

Block this in CI

PkgRadar gates new-ts-helper (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]