PkgRadar

Package evidence

@aws/[email protected]

Credential file access: matched ".aws"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@aws/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@aws/[email protected]"],"fail_on":"high"}'
Artifact bytes637,729
Previous version0.9.1
Published2026-05-25T00:10:25.565Z
SHA-2565184433a0e3d8491647a8a85997c4bf02d1cc9de84f070c986205c9e8ec5422d

Why flagged

What the scanner saw

Credential file access: matched ".aws"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
876Score
0.10.0Version
Status history (1 event)
  1. newavailable · risk high · score 876 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

sagemaker-naugrim

2 members · evidence strength 64

Evidence

Static findings

37 static · 0 from release diff · showing high-signal first.

Showing 30 of 33 findings.

SeverityKindPathDetailPoints
highCredential file accesspackage/src/lib/aws-profile-parser.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-command-handler.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-profile-manager.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-provisioners.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-loader.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-manager.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-validator.jsmatched ".aws"30
highCredential file accesspackage/src/lib/e2e-ci-recorder.jsmatched ".aws"30
highCredential file accesspackage/servers/hyperpod-cluster-picker/index.jsmatched ".aws"30
highCredential file accesspackage/servers/instance-sizer/index.jsmatched ".AWS"30
highCredential file accesspackage/servers/model-picker/index.jsmatched ".AWS"30
highCredential file accesspackage/servers/region-picker/index.jsmatched ".AWS"30
highCredential file accesspackage/src/lib/prompts/infrastructure-prompts.jsmatched ".aws"30
highCredential file accesspackage/src/lib/marketplace-flow.jsmatched ".aws"30
highCredential file accesspackage/src/lib/mcp-query-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/prompt-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/secrets-command-handler.jsmatched ".aws"30
highCredential file accesspackage/src/lib/secrets-prompt-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/sensitive-redactor.jsmatched "AWS_SECRET_ACCESS_KEY"30
highCredential file accesspackage/src/lib/template-manager.jsmatched ".aws"30
highCredential file accesspackage/servers/lib/catalogs/python-slim.jsonmatched ".aws"30
highCredential file accesspackage/templates/diffusors/start_server.shmatched ".aws"30
highCredential file accesspackage/templates/do/lib/wait.shmatched ".aws"30
highCredential file accesspackage/infra/ci-harness/bin/ci-harness.tsmatched ".AWS"30
highCredential file accesspackage/templates/hyperpod/pvc.yamlmatched ".aws"30
highCredential file accesspackage/templates/buildspec.ymlmatched "AWS_ACCESS_KEY"30
mediumRemote Payloadpackage/src/lib/architecture-sync.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/src/lib/schema-sync.jsmatched "raw.githubusercontent.com"12
mediumObfuscation Densitypackage/infra/ci-harness/package-lock.jsonhigh encoded/escaped-token density12
mediumRemote Payloadpackage/templates/code/start_server.shmatched "curl "12
Show all 37 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accesspackage/src/lib/aws-profile-parser.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-command-handler.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-profile-manager.jsmatched ".aws"30
highCredential file accesspackage/src/lib/bootstrap-provisioners.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-loader.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-manager.jsmatched ".aws"30
highCredential file accesspackage/src/lib/config-validator.jsmatched ".aws"30
highCredential file accesspackage/src/lib/e2e-ci-recorder.jsmatched ".aws"30
highCredential file accesspackage/servers/hyperpod-cluster-picker/index.jsmatched ".aws"30
highCredential file accesspackage/servers/instance-sizer/index.jsmatched ".AWS"30
highCredential file accesspackage/servers/model-picker/index.jsmatched ".AWS"30
highCredential file accesspackage/servers/region-picker/index.jsmatched ".AWS"30
highCredential file accesspackage/src/lib/prompts/infrastructure-prompts.jsmatched ".aws"30
highCredential file accesspackage/src/lib/marketplace-flow.jsmatched ".aws"30
highCredential file accesspackage/src/lib/mcp-query-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/prompt-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/secrets-command-handler.jsmatched ".aws"30
highCredential file accesspackage/src/lib/secrets-prompt-runner.jsmatched ".aws"30
highCredential file accesspackage/src/lib/sensitive-redactor.jsmatched "AWS_SECRET_ACCESS_KEY"30
highCredential file accesspackage/src/lib/template-manager.jsmatched ".aws"30
highCredential file accesspackage/servers/lib/catalogs/python-slim.jsonmatched ".aws"30
highCredential file accesspackage/templates/diffusors/start_server.shmatched ".aws"30
highCredential file accesspackage/templates/do/lib/wait.shmatched ".aws"30
highCredential file accesspackage/infra/ci-harness/bin/ci-harness.tsmatched ".AWS"30
highCredential file accesspackage/templates/hyperpod/pvc.yamlmatched ".aws"30
highCredential file accesspackage/templates/buildspec.ymlmatched "AWS_ACCESS_KEY"30
mediumRemote Payloadpackage/src/lib/architecture-sync.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/src/lib/schema-sync.jsmatched "raw.githubusercontent.com"12
mediumObfuscation Densitypackage/infra/ci-harness/package-lock.jsonhigh encoded/escaped-token density12
mediumRemote Payloadpackage/templates/code/start_server.shmatched "curl "12
mediumRemote Payloadpackage/templates/diffusors/start_server.shmatched "curl "12
mediumRemote Payloadpackage/templates/test/test_local_image.shmatched "curl "12
mediumRemote Payloadpackage/infra/ci-harness/lib/ci-harness-stack.tsmatched "curl "12
lowObfuscationpackage/src/lib/generation-validator.jsmatched "\\x1b"3
lowObfuscationpackage/src/lib/parameter-schema-validator.jsmatched "\\u2265"3
lowObfuscationpackage/src/lib/validation-report.jsmatched "\\x1b"3
lowObfuscationpackage/templates/deploy_notebook_generator.pymatched "\\u26a0"3

Manifest

Package metadata

Scripts1
  • testnode test.js
Dependencies1
  • @modelcontextprotocol/sdk^1.0.0