npm · registry.npmjs.org
openclaw-trimmed
Credential file access: matched ".npmrc"
Why PkgRadar flagged 1.0.3
| Severity | Signal | Evidence |
|---|---|---|
| medium | Credential file access | matched ".npmrc" · package/dist/install-package-dir-e3zQiAyh.js |
| medium | Credential file access | matched ".npmrc" · package/dist/npm-install-env-CneQB_SO.js |
| medium | Credential file access | matched ".npmrc" · package/dist/npm-managed-root-DrxaO7GL.js |
| medium | Credential file access | matched ".npmrc" · package/dist/install-package-dir-C17qrRMe.mjs |
| medium | Credential file access | matched ".npmrc" · package/dist/npm-install-env-CneQB_SO.mjs |
| medium | Credential file access | matched ".npmrc" · package/dist/npm-managed-root-D-4ZWw6c.mjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.0.3 | Review | 100 | 2026-05-26 |
1.0.4 | Review | 100 | 2026-05-26 |
1.0.1 | Low risk | 0 | 2026-05-25 |
1.0.2 | Low risk | 0 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]