PkgRadar

Package evidence

hermes-agent==0.19.0

Credential file access, Python Bun Js Exec, Py Runtime Base64 Decode +4 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
11
First published
May 2026
Publisher
Nous Research

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["hermes-agent==0.19.0"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["hermes-agent==0.19.0"],"fail_on":"high"}'
PublisherNous Research
Artifact bytes14,282,599
Previous versionnone
Published2026-07-20T18:37:28
SHA-256ac986bede64a2785436676c0ea084ec586574f8cb00a9d047e095b435d3e21c0

Why flagged

What the scanner saw

Credential file access

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
260Score
0.19.0Version
Status history (1 event)
  1. newavailable · risk high · score 260 · status changed

Evidence

Static findings

34 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accessmanifest30
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Dynamic Dangerous Importmanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumRemote Payloadmanifest12
mediumCredential file accessmanifest10
mediumCredential file accessmanifest10
Show all 34 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accessmanifest30
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPython Bun Js Execmanifest20
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Dynamic Dangerous Importmanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumPy Runtime Base64 Decodemanifest15
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumRemote Payloadmanifest12
mediumCredential file accessmanifest10
mediumCredential file accessmanifest10
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest3
lowSdist Has Setup Pymanifest0