PkgRadar

npm · registry.npmjs.org

tomevault

Llm Injection Payload: AI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore previous instructions" target=".ssh/id_rsa"

Why PkgRadar flagged 1.6.0

SeveritySignalEvidence
highLlm Injection PayloadAI-agent-directed instruction adjacent to credential exfil — prompt-injection payload (Shai-Hulud / SANDWORM_MODE). imperative="Ignore previous instructions" target=".ssh/id_rsa" · package/src/engine/scan-engine.mjs
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/src/commands/init.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.0High risk572026-06-15
1.3.0Review122026-06-14
1.5.0High risk572026-06-14
1.3.1Review122026-06-03
1.4.0Review172026-06-03

Block this in CI

PkgRadar gates tomevault (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]