Package evidence
@digitalworld/[email protected]
Suspicious Publish Context: {"package_age_days":0,"publisher":"johnclear","burst_same_day":0,"burst_week":0,"lure":null,"version_anomaly":true,"new_account":true}
Trust signals
Why this verdict
PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.
- Versions published
- 1
- First published
- Jun 2026
- Publisher
- johnclear
Recommended action
Review before promotingMixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@digitalworld/[email protected]"],"fail_on":"review"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@digitalworld/[email protected]"],"fail_on":"review"}'Why flagged
What the scanner saw
Suspicious Publish Context: {"package_age_days":0,"publisher":"johnclear","burst_same_day":0,"burst_week":0,"lure":null,"version_anomaly":true,"new_account":true}
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk review · score 10 · status changed
Evidence
Static findings
1 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Suspicious Publish Context | manifest | {"package_age_days":0,"publisher":"johnclear","burst_same_day":0,"burst_week":0,"lure":null,"version_anomaly":true,"new_account":true} | 10 |
Manifest
Package metadata
Scripts35
_buildpnpm run clean && pnpm run build:lib:all && pnpm run build:types:all_prettierprettier --ignore-path config/.prettierignore --write './src/**/*.ts' './test/**/*.{js,ts}'buildcross-env NODE_ENV=development pnpm run _buildbuild:librollup -cbuild:lib:allpnpm run build:lib && pnpm run build:lib:axiosbuild:lib:axioscross-env USE_AXIOS=true rollup -cbuild:prodcross-env NODE_ENV=production pnpm run _buildbuild:typestsc -p tsconfig.json && mkdir -p lib/esm/base/generated && cp src/base/generated/*.d.ts lib/esm/base/generated/build:types:allpnpm run build:types && pnpm run build:types:axiosbuild:types:axiostsc -p config/tsconfig.axios.json && mkdir -p lib/axios/esm/base/generated && cp src/base/generated/*.d.ts lib/axios/esm/base/generated/cleanrm -rf lib/ dist/ coverage/ jsdoc/ test/e2e/.sorobanclean:bundle-sizerm -rf node_modules lib/ dist/ coverage/ jsdoc/ test/e2e/.sorobandocspnpm docs:reference && pnpm docs:llms && pnpm docs:robots && pnpm docs:htaccess && pnpm docs:sitedocs:devastro devdocs:htaccesstsx scripts/build-htaccess.tsdocs:llmstsx scripts/build-llms.tsdocs:previewastro previewdocs:referencetsx scripts/build-docs.tsdocs:robotstsx scripts/build-robots.tsdocs:siteastro build && tsx scripts/build-md-siblings.tsdownload-sac-specnode scripts/download-sac-spec.jsfmtpnpm run _prettier && eslint src/ --fixpostbuild:libnode config/write-module-type.js lib/cjs commonjspostbuild:lib:axiosnode config/write-module-type.js lib/axios/cjs commonjspreversionpnpm run clean && pnpm run _prettier && pnpm run build:prod && pnpm run testsetupgit config blame.ignoreRevsFile .git-blame-ignore-revstestpnpm run test:node && pnpm run test:node:axios && pnpm run test:integration && pnpm run test:browsertest:allpnpm run test:node && pnpm run test:node:axios && pnpm run test:integration && pnpm run test:browser && pnpm run test:e2etest:browserpnpm run build:lib && vitest run --config config/vitest.config.browser.ts test/unit --coveragetest:browser:axiospnpm run build:lib:axios && cross-env TRANSPORT=axios vitest run --config config/vitest.config.browser.ts test/unit- …and 5 more.
Dependencies12
@noble/ed25519^3.1.0@noble/hashes^2.2.0@stellar/js-xdr4.0.0axios1.16.1base32.js^0.1.0bignumber.js^11.1.1buffer^6.0.3commander^14.0.3eventsource^4.1.0feaxios^0.0.23smol-toml^1.6.1uint8array-extras^1.5.0