PkgRadar

Package evidence

[email protected]

Known Indicator Filename: package/dist/core/bundle.js

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publisher0420.eth
Artifact bytes16,646,166
Previous version0.2.71
Published2026-05-24T07:27:35.341Z
SHA-25697d223dbaf65d970c462eaac0eac1f6d4ddad094c171c5c6c2045058f86bcbe4

Why flagged

What the scanner saw

Known Indicator Filename: package/dist/core/bundle.js

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
1215Score
0.2.72Version
Status history (1 event)
  1. newavailable · risk high · score 1215 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPstale

Known Indicator Filename — package/dist/core/bundle.js

2 members · evidence strength 70
Publisher / release actor burststale

0420.eth

2 members · evidence strength 64

Evidence

Static findings

124 static · 0 from release diff · showing high-signal first.

Showing 30 of 54 findings.

SeverityKindPathDetailPoints
highKnown Indicator Filenamepackage/dist/core/bundle.jspackage/dist/core/bundle.js45
highCredential file accesspackage/dist/utils/fs.jsmatched ".ssh"30
highCredential file accesspackage/dist/cli/interactive.jsmatched ".ssh"30
highCredential file accesspackage/dist/tools/runCommand.jsmatched ".ssh"30
highCredential file accesspackage/dist/providers/store.jsmatched ".ssh"30
highCredential file accesspackage/defaults/mcp-servers.jsonmatched ".aws"30
highCredential file accesspackage/package.jsonmatched ".npmrc"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/SKILL.jsonmatched ".azure"30
highCredential file accesspackage/skills/cco-astronomer-data-agents-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-data-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-data-engineering-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-railway-use-railway/scripts/dal.pymatched ".ssh"30
highCredential file accesspackage/skills/cco-sagemaker-ai-hyperpod-issue-report/scripts/hyperpod_issue_report.pymatched "kubeconfig"30
highCredential file accesspackage/skills/cco-sagemaker-ai-model-evaluation/scripts/nova_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-finetuning/templates/nova_rlvr_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-model-evaluation/scripts/reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-finetuning/templates/rlvr_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/references/recipes/cicd/examples/github-azd.ymlmatched ".AZURE"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/references/recipes/cicd/examples/github-bicep.ymlmatched ".AZURE"30
mediumRemote Payloadpackage/dist/design/index.jsmatched "curl "12
mediumRemote Payloadpackage/dist/mcp/installer.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/mcpAwareness.jsmatched "curl "12
mediumObfuscation Densitypackage/dist/cli/prompt.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/tools/runCommand.jsmatched "curl "12
mediumRemote Payloadpackage/dist/odin/store.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/dist/tools/spotify/triggers.jsmatched "curl "12
mediumRemote Payloadpackage/dist/tools/weather/weatherTools.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/workflowHints.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/workflowStrength.jsmatched "curl "12
mediumObfuscation Densitypackage/mcp-packages/package-lock.jsonhigh encoded/escaped-token density12
Show all 124 findings (low-signal and informational)

Showing 60 of 124 findings.

SeverityKindPathDetailPoints
highKnown Indicator Filenamepackage/dist/core/bundle.jspackage/dist/core/bundle.js45
highCredential file accesspackage/dist/utils/fs.jsmatched ".ssh"30
highCredential file accesspackage/dist/cli/interactive.jsmatched ".ssh"30
highCredential file accesspackage/dist/tools/runCommand.jsmatched ".ssh"30
highCredential file accesspackage/dist/providers/store.jsmatched ".ssh"30
highCredential file accesspackage/defaults/mcp-servers.jsonmatched ".aws"30
highCredential file accesspackage/package.jsonmatched ".npmrc"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/SKILL.jsonmatched ".azure"30
highCredential file accesspackage/skills/cco-astronomer-data-agents-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-data-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-data-engineering-analyzing-data/scripts/connectors.pymatched "GOOGLE_APPLICATION_CREDENTIALS"30
highCredential file accesspackage/skills/cco-railway-use-railway/scripts/dal.pymatched ".ssh"30
highCredential file accesspackage/skills/cco-sagemaker-ai-hyperpod-issue-report/scripts/hyperpod_issue_report.pymatched "kubeconfig"30
highCredential file accesspackage/skills/cco-sagemaker-ai-model-evaluation/scripts/nova_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-finetuning/templates/nova_rlvr_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-model-evaluation/scripts/reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-sagemaker-ai-finetuning/templates/rlvr_reward_function_source_template.pymatched ".aws"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/references/recipes/cicd/examples/github-azd.ymlmatched ".AZURE"30
highCredential file accesspackage/skills/cco-azure-azure-deploy/references/recipes/cicd/examples/github-bicep.ymlmatched ".AZURE"30
mediumRemote Payloadpackage/dist/design/index.jsmatched "curl "12
mediumRemote Payloadpackage/dist/mcp/installer.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/mcpAwareness.jsmatched "curl "12
mediumObfuscation Densitypackage/dist/cli/prompt.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/tools/runCommand.jsmatched "curl "12
mediumRemote Payloadpackage/dist/odin/store.jsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/dist/tools/spotify/triggers.jsmatched "curl "12
mediumRemote Payloadpackage/dist/tools/weather/weatherTools.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/workflowHints.jsmatched "curl "12
mediumRemote Payloadpackage/dist/core/workflowStrength.jsmatched "curl "12
mediumObfuscation Densitypackage/mcp-packages/package-lock.jsonhigh encoded/escaped-token density12
mediumRemote Payloadpackage/skills/cco-auth0-express-oauth2-jwt-bearer/scripts/bootstrap.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-auth0-auth0-android/scripts/utils/validation.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-auth0-auth0-expo/scripts/utils/validation.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-auth0-auth0-spa-js/scripts/utils/validation.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-auth0-auth0-swift/scripts/utils/validation.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-auth0-express-oauth2-jwt-bearer/scripts/utils/validation.mjsmatched "curl "12
mediumRemote Payloadpackage/skills/cco-railway-use-railway/scripts/analyze-postgres.pymatched "cUrl "12
mediumRemote Payloadpackage/skills/cco-astronomer-data-agents-analyzing-data/scripts/cli.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-data-analyzing-data/scripts/cli.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-data-engineering-analyzing-data/scripts/cli.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-sagemaker-ai-hyperpod-issue-report/scripts/hyperpod_issue_report.pymatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/skills/cco-astronomer-data-agents-analyzing-data/scripts/kernel.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-data-analyzing-data/scripts/kernel.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-data-engineering-analyzing-data/scripts/kernel.pymatched "curl "12
mediumRemote Payloadpackage/skills/cco-huggingface-skills-huggingface-llm-trainer/scripts/train_grpo_example.pymatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/skills/cco-fastly-agent-toolkit-fastly-ngwaf/scripts/assess_ngwaf_rules.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-huggingface-skills-huggingface-tool-builder/references/baseline_hf_api.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-huggingface-skills-huggingface-tool-builder/references/find_models_by_paper.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-huggingface-skills-huggingface-tool-builder/references/hf_enrich_models.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-huggingface-skills-huggingface-tool-builder/references/hf_model_papers_auth.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-sagemaker-ai-hyperpod-version-checker/scripts/hyperpod_check_versions.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-railway-use-railway/scripts/railway-api.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-brightdata-plugin-design-mirror/scripts/scrape_html.shmatched "curl "12
mediumRemote Payloadpackage/skills/cco-brightdata-plugin-design-mirror/scripts/screenshot.shmatched "curl "12
lowObfuscationpackage/dist/termio/ansi.jsmatched "\\x1b"3
lowObfuscationpackage/dist/cli/app.jsmatched "\\x1B"3
lowObfuscationpackage/dist/cli/blessedPrompt.jsmatched "\\x1b"3
lowObfuscationpackage/dist/cli/branding.jsmatched "\\x1b"3
lowObfuscationpackage/dist/tools/visual/browserImageSearch.jsmatched "\\u4e00"3
lowObfuscationpackage/dist/cli/bundleDialog.jsmatched "\\x1b"3

Manifest

Package metadata

Dependencies3
  • ajv^8.17.1
  • ajv-formats^3.0.1
  • js-yaml^4.1.0