PkgRadar

Package evidence

@namncqualgo/[email protected]

DNS / OAST exfiltration: matched "oastify.com"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
5
First published
Jun 2026
Publisher
clgslsm

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@namncqualgo/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@namncqualgo/[email protected]"],"fail_on":"high"}'
Publisherclgslsm
Artifact bytes1,601,307
Previous versionnone
Published2026-06-03T04:48:40.303Z
SHA-25621e05848f8ff5af5b5f479021158ba742b2ba8d5e49a8babf9336471bbd2800c

Why flagged

What the scanner saw

DNS / OAST exfiltration: matched "oastify.com"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
139Score
0.1.0Version
Status history (1 event)
  1. newavailable · risk high · score 139 · status changed

Evidence

Static findings

35 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/pypi/GHSA-f776-fp4w-266c.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/GHSA-p4fx-23fq-jfg6.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2025-49410.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2026-3724.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2026-3749.jsonmatched "oastify.com"30
Show all 35 findings (low-signal and informational)
SeverityKindPathDetailPoints
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/pypi/GHSA-f776-fp4w-266c.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/GHSA-p4fx-23fq-jfg6.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2025-49410.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2026-3724.jsonmatched "oastify.com"30
highDNS / OAST exfiltrationpackage/data/vulnerabilities/osv/npm/MAL-2026-3749.jsonmatched "oastify.com"30
lowCredential file accesspackage/data/vulnerabilities/osv/nuget/GHSA-28xm-prxc-5866.jsonmatched ".AWS\\"3
lowCredential file accesspackage/data/vulnerabilities/osv/pypi/GHSA-3363-2ph6-35wh.jsonmatched "id_rsa"3
lowCredential file accesspackage/data/vulnerabilities/osv/pypi/GHSA-5v57-8rxj-3p2r.jsonmatched "AWS_SECRET_ACCESS_KEY"3
lowCredential file accesspackage/data/vulnerabilities/osv/pypi/GHSA-8cxw-cc62-q28v.jsonmatched ".aws/"3
lowCredential file accesspackage/data/vulnerabilities/osv/nuget/GHSA-vc24-j8c5-2vw4.jsonmatched ".Azure/"3
lowCredential file accesspackage/data/vulnerabilities/supply-chain/malicious-packages/go.jsonmatched ".ssh/"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3149.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3151.jsonmatched ".ssh/"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3152.jsonmatched ".aws/"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3153.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3154.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3155.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3156.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3158.jsonmatched ".azure/"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3162.jsonmatched ".ssh/"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3754.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3755.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3756.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3758.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3762.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3763.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3764.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3765.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3766.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/osv/npm/MAL-2026-3772.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/supply-chain/malicious-packages/npm.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/vulnerabilities/supply-chain/dependency-confusion/patterns.jsonmatched ".npmrc"3
lowCredential file accesspackage/data/skills/logging-security/rules/redaction_patterns.jsonmatched "aws_secret_access_key"3
lowCredential file accesspackage/data/dictionaries/attack_techniques.yamlmatched "id_rsa"3
lowCredential file accesspackage/data/skills/cicd-security/checklists/github_actions_hardening.yamlmatched "AWS_ACCESS_KEY"3

Manifest

Package metadata

Optional dependencies5
  • @namncqualgo/secure-code-mcp-darwin-arm640.1.0
  • @namncqualgo/secure-code-mcp-darwin-x640.1.0
  • @namncqualgo/secure-code-mcp-linux-arm640.1.0
  • @namncqualgo/secure-code-mcp-linux-x640.1.0
  • @namncqualgo/secure-code-mcp-win32-x640.1.0