PkgRadar

Package evidence

@fased/[email protected]

Js Ssh Authorized Keys Implant, Webhook Exfil Endpoint, Remote Payload +3 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
53
First published
Jun 2026
Publisher
fased

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@fased/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@fased/[email protected]"],"fail_on":"high"}'
Publisherfased
Artifact bytes7,086,250
Previous version0.1.61
Published2026-07-16T15:00:11.067Z
SHA-256703a706c497a617f123a989f6f6d6448a5eb1b735996133ce126b3307e079879

Why flagged

What the scanner saw

Js Ssh Authorized Keys Implant

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
154Score
0.1.62Version
Status history (1 event)
  1. newavailable · risk high · score 154 · status changed

Evidence

Static findings

15 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highJs Ssh Authorized Keys Implantmanifest45
highWebhook Exfil Endpointmanifest40
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
Show all 15 findings (low-signal and informational)
SeverityKindPathDetailPoints
highJs Ssh Authorized Keys Implantmanifest45
highWebhook Exfil Endpointmanifest40
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
lowMessenger Bot Endpointmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowMessenger Bot Endpointmanifest5
lowMessenger Bot Endpointmanifest5
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0

Manifest

Package metadata

Dependencies38
  • @agentclientprotocol/sdk0.14.1
  • @clack/prompts^1.0.1
  • @fedify/fedify^2.3.1
  • @homebridge/ciao^1.3.5
  • @line/bot-sdk^10.6.0
  • @lydell/node-pty1.2.0-beta.3
  • @mariozechner/pi-agent-corenpm:@earendil-works/[email protected]
  • @mariozechner/pi-ainpm:@earendil-works/[email protected]
  • @mariozechner/pi-coding-agentnpm:@earendil-works/[email protected]
  • @mariozechner/pi-tuinpm:@earendil-works/[email protected]
  • @modelcontextprotocol/sdk1.29.0
  • @sinclair/typebox0.34.48
  • @solana/web3.js^1.98.0
  • ajv^8.18.0
  • chalk^5.6.2
  • chokidar^5.0.0
  • cli-highlight^2.1.11
  • commander^14.0.3
  • croner^10.0.1
  • dotenv^17.3.1
  • express^5.2.1
  • gaxios7.1.2
  • https-proxy-agent^7.0.6
  • ipaddr.js^2.3.0
  • jiti^2.6.1
  • json5^2.2.3
  • jszip^3.10.1
  • long^5.3.2
  • markdown-it^14.2.0
  • node-domexceptionnpm:@nolyfill/domexception@^1.0.28
  • …and 8 more.