PkgRadar

npm · registry.npmjs.org

openshamela

Credential file access: matched ".azure"

Why PkgRadar flagged 0.6.0

SeveritySignalEvidence
highCredential file accessmatched ".azure" · package/dist/cli/args.js
highCredential file accessmatched ".SSH" · package/dist/utils/clipboard.js
highCredential file accessmatched ".ssh" · package/examples/extensions/sandbox/index.ts
highCredential file accessmatched ".ssh" · package/examples/extensions/tool-override.ts
mediumRemote Payloadmatched "wget " · package/dist/core/export-html/vendor/highlight.min.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/core/export-html/vendor/highlight.min.js
mediumRemote Payloadmatched "github.com/${config.repo}/releases/download" · package/dist/utils/tools-manager.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/modes/interactive/theme/dark.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/examples/extensions/dynamic-resources/dynamic.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/modes/interactive/theme/light.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/examples/extensions/sandbox/index.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.0Review842026-05-24
0.5.1Review842026-05-24
0.5.0Review842026-05-24
0.4.0Review842026-05-24
0.3.0Review842026-05-24
0.2.0Review842026-05-24
0.1.0Review842026-05-24

Block this in CI

PkgRadar gates openshamela (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]