PkgRadar

Package evidence

@evermore.work/[email protected]

Credential file access, DNS / OAST exfiltration, Remote Payload +3 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@evermore.work/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@evermore.work/[email protected]"],"fail_on":"high"}'
Artifact bytes3,920,516
Previous version2026.522.0-canary.0
Published2026-05-22T08:29:34.575Z
SHA-2560c28bda0a43e92719c35b4e255fb7a34633646a177ff081356218cc792d6defc

Why flagged

What the scanner saw

Credential file access

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
307Score
2026.522.0-canary.1Version
Status history (1 event)
  1. newavailable · risk high · score 307 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPstale

DNS / OAST exfiltration

101 members · evidence strength 71

Evidence

Static findings

58 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accessmanifest30
highCredential file accessmanifest30
highDNS / OAST exfiltrationmanifest30
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumObfuscation Densitymanifest12
mediumObfuscation Densitymanifest12
mediumRemote Payloadmanifest12
mediumLarge Javascript Payloadmanifest10
Show all 58 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accessmanifest30
highCredential file accessmanifest30
highDNS / OAST exfiltrationmanifest30
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumObfuscation Densitymanifest12
mediumObfuscation Densitymanifest12
mediumRemote Payloadmanifest12
mediumLarge Javascript Payloadmanifest10
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3
lowObfuscationmanifest3

Manifest

Package metadata

Dependencies36
  • @aws-sdk/client-s3^3.888.0
  • @evermore.work/adapter-acpx-local2026.522.0-canary.1
  • @evermore.work/adapter-claude-local2026.522.0-canary.1
  • @evermore.work/adapter-codex-local2026.522.0-canary.1
  • @evermore.work/adapter-cursor-cloud2026.522.0-canary.1
  • @evermore.work/adapter-cursor-local2026.522.0-canary.1
  • @evermore.work/adapter-gemini-local2026.522.0-canary.1
  • @evermore.work/adapter-grok-local2026.522.0-canary.1
  • @evermore.work/adapter-openclaw-gateway2026.522.0-canary.1
  • @evermore.work/adapter-opencode-local2026.522.0-canary.1
  • @evermore.work/adapter-pi-local2026.522.0-canary.1
  • @evermore.work/adapter-utils2026.522.0-canary.1
  • @evermore.work/db2026.522.0-canary.1
  • @evermore.work/plugin-sdk2026.522.0-canary.1
  • @evermore.work/shared2026.522.0-canary.1
  • ajv^8.18.0
  • ajv-formats^3.0.1
  • better-auth1.4.18
  • chokidar^4.0.3
  • detect-port^2.1.0
  • dompurify^3.3.2
  • dotenv^17.0.1
  • drizzle-orm^0.45.2
  • embedded-postgres^18.1.0-beta.16
  • express^5.1.0
  • hermes-evermore-adapter2026.522.0-canary.1
  • jsdom^28.1.0
  • multer^2.1.1
  • open^11.0.0
  • pino^9.6.0
  • …and 6 more.