PkgRadar

Package evidence

@chachamaru127/[email protected]

Credential file access: matched "GITHUB_TOKEN"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@chachamaru127/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@chachamaru127/[email protected]"],"fail_on":"high"}'
Publisherchachamaru127
Artifact bytes8,418,863
Previous version0.24.0
Published2026-05-22T03:57:50.517Z
SHA-256b718a4dbd13661251b17da16a5a08cf0050e99a78a41a6a49e3ad6f67adbc9d3

Why flagged

What the scanner saw

Credential file access: matched "GITHUB_TOKEN"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
207Score
0.24.1Version
Status history (1 event)
  1. newavailable · risk high · score 207 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

chachamaru127

3 members · evidence strength 74

Evidence

Static findings

36 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspackage/memory-server/src/sync/github-connector.tsmatched "GITHUB_TOKEN"30
mediumRemote Payloadpackage/mcp-server/dist/index.jsmatched "raw.githubusercontent.com"12
mediumObfuscation Densitypackage/mcp-server/dist/index.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/scripts/harness-mem-client.shmatched "curl "12
mediumRemote Payloadpackage/scripts/harness-mem-proof-pack.shmatched "curl "12
mediumRemote Payloadpackage/scripts/hook-handlers/memory-skill-finalize.shmatched "curl "12
mediumRemote Payloadpackage/scripts/s105-proof-bundle.shmatched "curl "12
mediumRemote Payloadpackage/scripts/test-integration.shmatched "curl "12
mediumRemote Payloadpackage/memory-server/src/llm/ollama-provider.tsmatched "curl "12
Show all 36 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accesspackage/memory-server/src/sync/github-connector.tsmatched "GITHUB_TOKEN"30
mediumRemote Payloadpackage/mcp-server/dist/index.jsmatched "raw.githubusercontent.com"12
mediumObfuscation Densitypackage/mcp-server/dist/index.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/scripts/harness-mem-client.shmatched "curl "12
mediumRemote Payloadpackage/scripts/harness-mem-proof-pack.shmatched "curl "12
mediumRemote Payloadpackage/scripts/hook-handlers/memory-skill-finalize.shmatched "curl "12
mediumRemote Payloadpackage/scripts/s105-proof-bundle.shmatched "curl "12
mediumRemote Payloadpackage/scripts/test-integration.shmatched "curl "12
mediumRemote Payloadpackage/memory-server/src/llm/ollama-provider.tsmatched "curl "12
lowObfuscationpackage/harness-mem-ui/src/static-parity/assets/index-BOg4-YO2.jsmatched "\\u00C0"3
lowObfuscationpackage/mcp-server/dist/index.jsmatched "atob("3
lowObfuscationpackage/memory-server/tests/unit/audio-ingester.test.tsmatched "\\x24"3
lowObfuscationpackage/memory-server/src/core/core-utils.tsmatched "\\u30A0"3
lowObfuscationpackage/memory-server/src/core/current-value-compression.tsmatched "\\u3000"3
lowObfuscationpackage/memory-server/src/consolidation/deduper.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/ingest/document-parser.tsmatched "fromCharCode"3
lowObfuscationpackage/memory-server/src/consolidation/extractor.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/embedding/fallback.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/benchmark/fixture-integrator.tsmatched "\\u3041"3
lowObfuscationpackage/memory-server/src/core/ingest-coordinator.tsmatched "\\u0000"3
lowObfuscationpackage/memory-server/tests/unit/inject-counterfactual-eval.test.tsmatched "Eval("3
lowObfuscationpackage/memory-server/src/benchmark/inject-counterfactual-eval.tsmatched "Eval("3
lowObfuscationpackage/memory-server/src/core/nugget-splitter.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/core/observation-store.tsmatched "Buffer.from(input, \"base64"3
lowObfuscationpackage/memory-server/src/vector/providers.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/benchmark/qa-quality-check.tsmatched "\\u3041"3
lowObfuscationpackage/memory-server/src/embedding/query-analyzer.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/tests/unit/query-expander.test.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/embedding/query-expander.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/benchmark/retrospective-eval.tsmatched "Eval("3
lowObfuscationpackage/memory-server/src/retrieval/router.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/benchmark/run-integrated-benchmark.tsmatched "\\u3041"3
lowObfuscationpackage/memory-server/src/benchmark/run-retrospective-ci.tsmatched "Eval("3
lowObfuscationpackage/scripts/s108-temporal-fixture-expansion.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/rerank/simple-reranker.tsmatched "\\u3040"3
lowObfuscationpackage/memory-server/src/consolidation/worker.tsmatched "\\u3040"3

Manifest

Package metadata

Scripts17
  • benchmarkcd memory-server && bun run src/benchmark/run-ci.ts
  • benchmark:pilot30bash scripts/bench-pilot-30usd.sh
  • benchmark:pilot30:dry-runbash scripts/bench-pilot-30usd.sh --dry-run
  • benchmark:swebench-probash scripts/bench-swebench-pro.sh
  • benchmark:swebench-pro:dry-runbash scripts/bench-swebench-pro.sh --dry-run
  • benchmark:swebench-pro:smokebash scripts/bench-swebench-pro.sh --repo-path ../SWE-bench_Pro-os --subset-manifest smoke --runner local-docker --model gpt-5-mini --mode on-off --dry-run
  • benchmark:tau3bash scripts/bench-tau3.sh
  • benchmark:tau3:dry-runbash scripts/bench-tau3.sh --dry-run
  • benchmark:tau3:smokebash scripts/bench-tau3.sh --repo-path ../tau2-bench --domain retail --task-split-name base --num-tasks 1 --num-trials 1 --mode on-off --dry-run
  • benchmark:tune-adaptivecd memory-server && bun run src/benchmark/adaptive-tuning.ts
  • codex:doctornode scripts/harness-mem.js doctor --platform codex
  • codex:setupbash scripts/setup-codex-memory.sh
  • poc:graph-kuzunpx tsx scripts/graph-store-poc-kuzu.ts
  • poc:graph-sqlitebun run scripts/graph-store-poc-sqlite-cte.ts
  • test(cd memory-server && bun run test) && bash scripts/run-bun-test-batches.sh tests sdk/tests mcp-server/tests
  • test:e2ecd harness-mem-ui && bunx playwright test
  • test:uicd harness-mem-ui && bunx vitest
Dependencies2
  • @huggingface/transformers3.8.1
  • sharp0.34.5
Optional dependencies2
  • @img/sharp-libvips-darwin-arm641.2.4
  • sqlite-vec-darwin-arm640.1.9