PkgRadar

npm · registry.npmjs.org

oblien

Credential file access: matched ".ssh"

Why PkgRadar flagged 2.2.35

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/dist/cli/commands/scp.js
highCredential file accessmatched ".ssh" · package/dist/cli/commands/ssh-util.js
highCredential file accessmatched ".ssh" · package/dist/cli/commands/ssh.js
highCredential file accessmatched ".ssh" · package/dist/mcp/tools.js
highCredential file accessmatched ".ssh" · package/dist/workspace-handle.js
highCredential file accessmatched ".ssh" · package/dist/workspace.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.35Review502026-05-24
2.2.36Review502026-05-24

Related campaigns

Block this in CI

PkgRadar gates oblien (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]