PkgRadar

Package evidence

@rzl-zone/[email protected]

Credential file access: matched ".npmrc"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@rzl-zone/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@rzl-zone/[email protected]"],"fail_on":"high"}'
Publisherrzlzone
Artifact bytes805,281
Previous version3.13.1
Published2026-05-24T01:28:57.166Z
SHA-2560548d3fc7ead77e0d224018703cca93e38a8655ddec5052ce745a658c54d5f44

Why flagged

What the scanner saw

Credential file access: matched ".npmrc"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
123Score
3.14.0-beta.0Version
Status history (1 event)
  1. newavailable · risk high · score 123 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

rzlzone

2 members · evidence strength 64
Repeated static TTPstale

Credential file access — matched ".SSH"

84 members · evidence strength 90

Evidence

Static findings

14 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspackage/dist/parsers-i8WEeMJl.cjsmatched ".npmrc"30
highCredential file accesspackage/dist/parsers-BBAE_xVM.jsmatched ".npmrc"30
highCredential file accesspackage/dist/rzl-utils.global.jsmatched ".SSH"30
Show all 14 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accesspackage/dist/parsers-i8WEeMJl.cjsmatched ".npmrc"30
highCredential file accesspackage/dist/parsers-BBAE_xVM.jsmatched ".npmrc"30
highCredential file accesspackage/dist/rzl-utils.global.jsmatched ".SSH"30
lowObfuscationpackage/dist/formatter-ekJQF_bA-BepnCBkQ.cjsmatched "atob("3
lowObfuscationpackage/dist/isValidDomain-D_x7uNIu.cjsmatched "\\u0E00"3
lowObfuscationpackage/dist/parsing-DGjB8cwr.cjsmatched "\\u00A0"3
lowObfuscationpackage/dist/punyCode-DHTLhGdD.cjsmatched "\\x7F"3
lowObfuscationpackage/dist/urls-NCzPepe2.cjsmatched "\\u0000"3
lowObfuscationpackage/dist/formatter-ekJQF_bA-xLD9mGk4.jsmatched "atob("3
lowObfuscationpackage/dist/isValidDomain-CDtNOhMc.jsmatched "\\u0E00"3
lowObfuscationpackage/dist/parsing-D9tbKQ0v.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/punyCode-Deb1Mrkc.jsmatched "\\x7F"3
lowObfuscationpackage/dist/rzl-utils.global.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/urls-EoWslGgg.jsmatched "\\u0000"3

Manifest

Package metadata

Scripts9
  • barrelpnpm run barrel:generate && pnpm run barrel:generate && pnpm run barrel:remove-comment-dist
  • barrel:generatenpx barrelsby --config barrelsby.config.json
  • barrel:remove-comment-disttsx scripts/removeBarrelsbyComment.ts
  • buildpnpm run barrel && tsdown
  • check-publishpnpm run build && pnpm pack --dry-run
  • check-types:packagetsc --noEmit
  • linteslint
  • release-patchpnpm version patch && git push && git push --tags && pnpm publish
  • test:utils-jsvitest run
Dependencies5
  • @rzl-zone/node-only0.0.11-beta.0
  • date-fns^4.1.0
  • libphonenumber-js^1.13.1
  • tailwind-merge-v2npm:tailwind-merge@^2
  • tailwind-merge-v3npm:tailwind-merge@^3