PkgRadar

Package evidence

@vm0/[email protected]

Shipped Live Secret, Credential file access, Obfuscation Density +1 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
822Established · −30% score
First published
Nov 2025
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@vm0/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@vm0/[email protected]"],"fail_on":"high"}'
Artifact bytes3,813,689
Previous version9.204.3
Published2026-06-24T03:27:52.259Z
SHA-2563e23309fd44827b5afdb8f078ccea445f90e4a3566415c5f3505512bdcd3ae5a

Why flagged

What the scanner saw

Shipped Live Secret

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
34Score
9.204.4Version
Status history (1 event)
  1. newavailable · risk high · score 34 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPactive

Shipped Live Secret

92 members · evidence strength 90
Repeated static TTPcandidate

Shipped Live Secret

92 members · max score 156

Evidence

Static findings

12 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
Show all 12 findings (low-signal and informational)
SeverityKindPathDetailPoints
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
highShipped Live Secretmanifest45
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0

Manifest

Package metadata

Dependencies1
  • ably^2.21.0