PkgRadar

Package evidence

@chen86860/[email protected]

Tls Verification Disabled, Credential file access, Large Javascript Payload

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
4
First published
Jun 2026
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@chen86860/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@chen86860/[email protected]"],"fail_on":"review"}'
Artifact bytes8,184,641
Previous version3.0.1
Published2026-06-29T07:42:32.463Z
SHA-25663e14f30352b51ce08cb2d906663e11ecc4e43c0edf55eca294d2b9d90a9ec49

Why flagged

What the scanner saw

Tls Verification Disabled

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
55Score
3.0.2Version
Status history (1 event)
  1. newavailable · risk review · score 55 · status changed

Evidence

Static findings

66 static · 0 from release diff · showing high-signal first.

Showing 30 of 31 findings.

SeverityKindPathDetailPoints
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
Show all 66 findings (low-signal and informational)

Showing 60 of 66 findings.

SeverityKindPathDetailPoints
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5

Manifest

Package metadata

Dependencies5
  • @fig/autocomplete-generators^2.4.0
  • @fig/autocomplete-helpers^1.0.7
  • semver^7.8.5
  • strip-json-comments^5.0.3
  • yaml^2.9.0