PkgRadar

npm · registry.npmjs.org

unuko

Credential file access: matched ".ssh"

Why PkgRadar flagged 0.1.10

SeveritySignalEvidence
highCredential file accessmatched ".ssh" · package/assets/sim-backend/dist/index.js
highCredential file accessmatched ".ssh" · package/dist/index.js
highCredential file accessmatched ".ssh" · package/assets/sim-frontend/dist/assets/shell-BZaILY8J.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/assets/sim-frontend/dist/assets/freemarker2-BODJhJoM.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/assets/sim-frontend/dist/assets/yaml.worker-ClsZXTL9.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/assets/sim-frontend/dist/assets/yaml.worker-ClsZXTL9.js
mediumRemote Payloadmatched "curl " · package/lima.yaml
mediumLarge Javascript Payload2543271 bytes · package/assets/sim-frontend/dist/assets/editor.api-DDKD6Td5.js
mediumLarge Javascript Payload2181346 bytes · package/assets/sim-frontend/dist/assets/index-D-fPm94M.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.10Review942026-05-24
0.1.9Review942026-05-24
0.1.8Review942026-05-24
0.1.7Review942026-05-24
0.1.6Review942026-05-24
0.1.5Review942026-05-24
0.1.4Review942026-05-24

Related campaigns

Block this in CI

PkgRadar gates unuko (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]