PkgRadar

npm · registry.npmjs.org

surgio

Credential file access: matched ".AWS"

Why PkgRadar flagged 3.15.0

SeveritySignalEvidence
highCredential file accessmatched ".AWS" · package/build/utils/index.js
mediumRemote Payloadmatched "cUrl " · package/build/config.js
mediumRemote Payloadmatched "curl " · package/build/constant/constant.js

Scanned versions

VersionVerdictScoreScanned (UTC)
3.15.0Review542026-05-24
3.16.0Review542026-05-24

Related campaigns

Block this in CI

PkgRadar gates surgio (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]