PkgRadar

Package evidence

[email protected]

Credential File Packaged, Obfuscation Density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
9
Versions published
2
First published
May 2026
Publisher
zagabe

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Publisherzagabe
Artifact bytes13,329,654
Previous versionnone
Published2026-05-29T15:21:13.732Z
SHA-2567741cb67042c095a3119fe7f998af261ca6eafa0056b40447325bc831c007cc3

Why flagged

What the scanner saw

Credential File Packaged

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
60Score
1.0.0Version
Status history (2 events)
  1. availableavailable · risk review · score 60 · status available -> available, risk high -> review, score 100 -> 60
  2. newavailable · risk high · score 100 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

Publisher burst: zagabe

4 members · evidence strength 78

Evidence

Static findings

24 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
Show all 24 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
mediumCredential File Packagedmanifest15
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0

Manifest

Package metadata

Dependencies6
  • @tailwindcss/vite^4.3.0
  • axios^1.16.1
  • react^19.2.6
  • react-dom^19.2.6
  • react-router-dom^7.15.1
  • tailwindcss^4.3.0