Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["@ductape/[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["@ductape/[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Credential file access: matched ".AWS"
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 354 · status changed
Related candidates
Linked campaigns and clusters
feekayo
3 members · evidence strength 77Evidence
Static findings
16 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential file access | package/dist/brokers/utils/broker.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/brokers/brokers.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/validators/joi-validators/create.productStorage.validator.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/utils/functions.utils.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/processor/services/processor.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/services/products.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/storage-cloud-link.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/storage.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/processor/utils/storage.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/utils/storage.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/package.json | matched ".aws" | 30 |
| medium | Remote Payload | package/dist/brokers/brokers.service.js | matched "cUrl " | 12 |
Show all 16 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| high | Credential file access | package/dist/brokers/utils/broker.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/brokers/brokers.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/validators/joi-validators/create.productStorage.validator.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/utils/functions.utils.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/processor/services/processor.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/products/services/products.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/storage-cloud-link.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/storage.service.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/processor/utils/storage.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/dist/storage/utils/storage.util.js | matched ".AWS" | 30 |
| high | Credential file access | package/package.json | matched ".aws" | 30 |
| medium | Remote Payload | package/dist/brokers/brokers.service.js | matched "cUrl " | 12 |
| low | Obfuscation | package/dist/database/presave/presave-processor.js | matched "\\u0300" | 3 |
| low | Obfuscation | package/dist/storage/storage.service.js | matched "Buffer.from(rawPayload, 'base64" | 3 |
| low | Obfuscation | package/dist/processor/utils/storage.util.js | matched "Buffer.from(data, \"base64" | 3 |
| low | Obfuscation | package/dist/storage/utils/storage.util.js | matched "Buffer.from(data, 'base64" | 3 |
Manifest
Package metadata
Scripts57
buildtscdocstypedoc --out docs srcparity:fixturests-node tools/parity-fixtures-gen.tspopulate:consumersts-node src/test/populate.consumers.tspopulate:db:mongots-node src/test/populate.db.mongo.tspopulate:db:mysqlts-node src/test/populate.db.mysql.tspopulate:db:postgrests-node src/test/populate.db.postgres.tspopulate:graph:neo4jts-node src/test/populate.graph.neo4j.tspopulate:graph:neo4j2ts-node src/test/populate.graph.neo4j2.tspopulate:messagingts-node src/test/populate.messaging.tspopulate:sessionts-node src/test/populate.session.tspopulate:storage:awsts-node src/test/populate.storage.aws.tspopulate:storage:azurets-node src/test/populate.storage.azure.tspopulate:storage:gcpts-node src/test/populate.storage.gcp.tspopulate:vector:pineconets-node src/test/populate.vector.pinecone.tspopulate:vector:qdrantts-node src/test/populate.vector.qdrant.tspopulate:vector:weaviatets-node src/test/populate.vector.weaviate.tspopulate:vector:weaviate2ts-node src/test/populate.vector.weaviate2.tspopulate:workflowsts-node src/test/populate.workflows.tsprepublishOnlynpm run buildservenodemon --exec ts-node ./src/index.tssharonts-node src/test/sharon.tstestjesttest:appnodemon --exec ts-node src/test/test.app.tstest:broker-messagesnodemon --exec ts-node src/test/test.broker-messages.tstest:cachesnodemon --exec ts-node src/test/test.caches.tstest:coveragejest --coveragetest:db:dynamonodemon --exec ts-node src/test/test.database.dynamo.tstest:db:mongonodemon --exec ts-node src/test/test.database.mongo.tstest:db:mysqlnodemon --exec ts-node src/test/test.database.mysql.ts- …and 27 more.
Dependencies33
@aws-sdk/client-sqs^3.750.0@azure/storage-blob^12.26.0@google-cloud/pubsub^4.10.0@types/redis^4.0.11amqplib^0.10.5aws-sdk^2.1692.0axios^1.5.0bson-objectid^2.0.4bullmq^5.58.0crypto-js^4.2.0date-fns^4.1.0dt-sql-parser^4.0.2firebase-admin^13.0.1form-data^4.0.1google-auth-library^9.15.1gtoken^7.1.0handlebars^4.7.8ioredis^5.7.0joi^17.7.0js-yaml^4.1.0jsonwebtoken^9.0.2jwa^2.0.1jws^4.0.0kafkajs^2.2.4lodash^4.17.21mongodb^6.14.2nats^2.29.3nodemailer^6.10.0pg^8.13.3redis^4.7.0- …and 3 more.
Optional dependencies3
arangojs^10.1.2gremlin^3.8.0neo4j-driver^6.0.1