PkgRadar

npm · registry.npmjs.org

psst-cli

Credential file access: matched ".aws"

Why PkgRadar flagged 0.7.0

SeveritySignalEvidence
highCredential file accessmatched ".aws" · package/dist/vault/aws-backend.js
highCredential file accessmatched ".AWS" · package/dist/vault/config.js
highCredential file accessmatched ".AWS" · package/dist/commands/init.js
highCredential file accessmatched ".aws" · package/dist/vault/vault.js
highCredential file accessmatched ".aws" · package/src/vault/aws-backend.ts
highCredential file accessmatched ".AWS" · package/src/vault/config.test.ts
highCredential file accessmatched ".AWS" · package/src/vault/config.ts
highCredential file accessmatched ".aws" · package/src/commands/init.test.ts
highCredential file accessmatched ".AWS" · package/src/commands/init.ts
highCredential file accessmatched ".aws" · package/src/vault/vault.ts
mediumRemote Payloadmatched "curl " · package/dist/main.js
mediumRemote Payloadmatched "curl " · package/src/main.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0Review1242026-05-24
0.7.1Review1242026-05-24

Related campaigns

Block this in CI

PkgRadar gates psst-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]