PkgRadar

Package evidence

@vm0/[email protected]

Shipped Live Secret, Credential file access, Obfuscation Density +1 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
10,281Mainstream · −50% score
Versions published
821Established · −30% score
First published
Nov 2025
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@vm0/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@vm0/[email protected]"],"fail_on":"high"}'
Artifact bytes3,814,104
Previous version9.204.2
Published2026-06-24T01:08:18.224Z
SHA-2565e671caeed71f02d8bf306d3060d29e184e32081daf4e96616205a7647c1bd8a

Why flagged

What the scanner saw

Shipped Live Secret

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
34Score
9.204.3Version
Status history (1 event)
  1. newavailable · risk high · score 34 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPactive

Shipped Live Secret

92 members · evidence strength 90
Repeated static TTPcandidate

Shipped Live Secret

92 members · max score 156

Evidence

Static findings

12 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
Show all 12 findings (low-signal and informational)
SeverityKindPathDetailPoints
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0

Manifest

Package metadata

Dependencies1
  • ably^2.21.0