PkgRadar

npm · registry.npmjs.org

token-usage-tracker

Credential file access: matched ".ssh"

Why PkgRadar flagged 1.5.1

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/lib/scanner-core.js
highCredential file accessmatched "github_token" · package/lib/trap-core.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/lib/trap-core.js
highInstall-time lifecycle scriptpostinstall="node lib/setup.js" · package.json
highInstall Lifecycle Remote Or Execpostinstall="node lib/setup.js" · package.json
mediumRemote Payloadmatched "webhook.site" · package/lib/scanner-core.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/lib/trap-core.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.1-securityLow risk02026-05-24
1.5.1High risk1492026-05-24
1.4.0High risk1492026-05-24
1.5.0High risk1492026-05-24

Block this in CI

PkgRadar gates token-usage-tracker (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]
token-usage-tracker — npm security scan | PkgRadar