PkgRadar

npm · registry.npmjs.org

pi-studio

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.9.16

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/client/studio-client.js
highCredential file accessmatched ".SSH" · package/shared/studio-ssh-hint.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/themes/pi-studio-dark.json
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/themes/pi-studio-light.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.32Low risk02026-06-10
0.9.31Low risk02026-06-10
0.9.30Low risk02026-06-09
0.9.29Low risk02026-06-08
0.9.28Low risk02026-06-08
0.9.27Low risk02026-06-08
0.9.26Low risk02026-06-03
0.9.25Low risk02026-06-01
0.9.24Low risk02026-06-01
0.9.23Low risk02026-05-31
0.9.22Low risk02026-05-29
0.9.21Low risk02026-05-28
0.9.20Low risk02026-05-27
0.9.19Low risk02026-05-26
0.9.18Low risk02026-05-25
0.9.16Review602026-05-24
0.9.17Review602026-05-24

Related campaigns

Block this in CI

PkgRadar gates pi-studio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]