PkgRadar

Package evidence

@panguard-ai/[email protected]

Known Indicator Filename, Credential file access, Obfuscation Density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
36
First published
Mar 2026
Publisher
panguard0414

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@panguard-ai/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@panguard-ai/[email protected]"],"fail_on":"high"}'
Publisherpanguard0414
Artifact bytes3,756,451
Previous version2.0.2
Published2026-04-17T00:13:29.986Z
SHA-256c04105592d8384dcd7f4bfb76d100eb8404f2cf2e43d162216096f37aa9629d9

Why flagged

What the scanner saw

Known Indicator Filename

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
112Score
2.0.3Version
Status history (2 events)
  1. availableavailable · risk high · score 112 · status available -> available, risk high -> high, score 142 -> 112
  2. newavailable · risk high · score 142 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burstactive

Publisher burst: panguard0414

59 members · evidence strength 84
Publisher / release actor burstcandidate

Publisher burst: panguard0414

59 members · max score 240

Evidence

Static findings

9 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
Show all 9 findings (low-signal and informational)
SeverityKindPathDetailPoints
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
highKnown Indicator Filenamemanifest45
lowCredential file accessmanifest3
lowCredential file accessmanifest3
lowCredential file accessmanifest3
lowCredential file accessmanifest3
lowObfuscation Densitymanifest0

Manifest

Package metadata

Dependencies11
  • @panguard-ai/atr1.5.1
  • @panguard-ai/core1.3.3
  • @panguard-ai/panguard-mcp1.3.2
  • @panguard-ai/panguard-skill-auditor1.4.5
  • @panguard-ai/panguard-trap1.3.1
  • @panguard-ai/scan-core1.4.2
  • @panguard-ai/security-hardening1.0.1
  • agent-threat-rules2.0.0
  • js-yaml^4.1.0
  • ws^8.19.0
  • zod^3.24.0