PkgRadar

npm · registry.npmjs.org

pinnedai

Credential file access: matched "AWS_ACCESS_KEY"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
highNew Lifecycle Script Vs Previouspostinstall added in 0.1.0 vs 0.0.1: "node scripts/postinstall.cjs" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.6.2Review72026-06-12
0.6.1Review72026-06-11
0.6.0Review72026-06-11
0.1.0High risk502026-06-10
0.5.0-beta.8Review72026-06-08
0.4.5Review72026-06-08
0.4.4Review72026-06-07
0.4.3Review102026-06-07
0.4.2Review72026-06-07
0.4.1Review72026-06-07
0.4.0Review72026-06-06
0.3.3Review72026-06-06
0.3.1Review72026-06-05
0.3.2Review72026-06-05
0.3.0Review102026-06-05
0.2.21Review102026-06-04
0.2.20Review72026-06-04
0.2.18Review72026-06-04
0.2.16Review72026-06-03
0.2.17Review72026-06-03
0.2.14Review102026-06-02
0.2.13Review102026-06-02
0.2.12Review102026-06-02
0.2.10Review102026-06-02
0.2.11Review102026-06-02
0.2.7Review102026-06-02
0.2.6Review102026-06-02
0.2.4Review102026-06-02
0.2.5Review102026-06-02
0.2.2Review102026-06-02
0.2.3Review102026-06-02
0.2.1Review102026-06-02
0.2.0Review102026-06-02
0.1.2Review102026-06-02
0.1.1Review102026-06-02
0.0.1Low risk02026-05-27

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Block this in CI

PkgRadar gates pinnedai (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]