PkgRadar

npm · registry.npmjs.org

nexus-prime

Credential file access: matched "GITHUB_TOKEN"

Why PkgRadar flagged 7.9.30

SeveritySignalEvidence
highCredential file accessmatched "GITHUB_TOKEN" · package/dist/engines/github-bridge.js
highCredential file accessmatched "GITHUB_TOKEN" · package/dist/engines/guardrails-bridge.js
highInstall Lifecycle Remote Or Execpostinstall="node -e \"const fs=require('fs'); const cleanup='dist/postinstall/cleanup.js'; if (fs.existsSync(cleanup)) { import('./'+cleanup).catch(()=>{}); } const p='dist/postinstall-bootstrap.js'; if (fs.existsSync(p)) { import('./'+p); }\"" · package.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/engines/guardrails-bridge.js

Scanned versions

VersionVerdictScoreScanned (UTC)
7.9.30High risk972026-06-13
7.9.29High risk972026-06-13
7.9.28High risk972026-06-10
7.9.26High risk972026-06-10
7.9.27High risk972026-06-10
7.9.25High risk672026-06-10
7.9.31High risk672026-06-10
7.9.33High risk672026-06-10
7.9.24High risk672026-06-10
7.9.23High risk972026-06-10
7.10.0Review52026-06-04
7.9.40Review32026-06-03
7.9.39Review32026-06-02
7.9.38Review32026-06-02
7.9.37Review32026-06-02
7.9.36Review52026-06-01
7.9.34Review32026-06-01
7.9.35Review52026-06-01

Campaign attribution

Part of the Clob dropper campaign.

Related campaigns

Block this in CI

PkgRadar gates nexus-prime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]