PkgRadar

Package evidence

[email protected]

Js Fs Walk Exfil, Js Remote Npm Install, Remote Payload +5 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
92
Versions published
87Established · −30% score
First published
Dec 2025
Publisher
jobrayan

Effective trust discount applied: 30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publisherjobrayan
Artifact bytes19,352,015
Previous version3.0.7
Published2026-06-26T08:48:10.583Z
SHA-25634272545f7b88efa378b75f24122e5a99a9b7a364001f42bb45e0bdb71b81421

Why flagged

What the scanner saw

Js Fs Walk Exfil

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
214Score
3.0.8Version
Status history (1 event)
  1. newavailable · risk high · score 214 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burstactive

Publisher burst: jobrayan

2 members · evidence strength 61
Publisher / release actor burstcandidate

Publisher burst: jobrayan

2 members · max score 214

Evidence

Static findings

67 static · 1 from release diff · showing high-signal first.

Showing 30 of 58 findings.

SeverityKindPathDetailPoints
highJs Fs Walk Exfilpackage/dist/chunk-12dkd74n.js45
highJs Fs Walk Exfilpackage/dist/chunk-3q2d4xh5.js45
highJs Fs Walk Exfilpackage/dist/chunk-am5pq8nt.js45
highJs Fs Walk Exfilpackage/dist/chunk-b8d24ts4.js45
highJs Fs Walk Exfilpackage/dist/chunk-gdd0nxj3.js45
highJs Fs Walk Exfilpackage/dist/chunk-hp3b6k4j.js45
highJs Remote Npm Installpackage/dist/chunk-nn1ayzr0.js45
highJs Fs Walk Exfilpackage/dist/chunk-pt667scp.js45
highJs Fs Walk Exfilpackage/dist/chunk-pz313yq8.js45
highJs Fs Walk Exfilpackage/dist/chunk-whttf0jv.js45
highJs Fs Walk Exfilpackage/dist/chunk-y01frwjd.js45
highJs Fs Walk Exfilpackage/dist/chunk-y9b18qce.js45
highNew Lifecycle Script Vs Previouspackage.json40
mediumRemote Payloadpackage/dist/chunk-am5pq8nt.js12
mediumRemote Payloadpackage/dist/chunk-b8d24ts4.js12
mediumRemote Payloadpackage/dist/chunk-hp3b6k4j.js12
mediumRemote Payloadpackage/dist/chunk-pt667scp.js12
mediumRemote Payloadpackage/dist/chunk-pz313yq8.js12
mediumRemote Payloadpackage/dist/chunk-y9b18qce.js12
mediumCredential file accesspackage/dist/chunk-12dkd74n.js10
mediumCredential file accesspackage/dist/chunk-2fv9089a.js10
mediumCredential file accesspackage/dist/chunk-2rnhm735.js10
mediumCredential file accesspackage/dist/chunk-3q2d4xh5.js10
mediumCredential file accesspackage/dist/chunk-4j5qzvpm.js10
mediumCredential file accesspackage/dist/chunk-4wqw507q.js10
mediumCredential file accesspackage/dist/chunk-4zpqh818.js10
mediumCredential file accesspackage/dist/chunk-5zensta2.js10
mediumCredential file accesspackage/dist/chunk-6rqp5q3j.js10
mediumCredential file accesspackage/dist/chunk-6x2asdvn.js10
mediumCredential file accesspackage/dist/chunk-71pxbqa6.js10
Show all 68 findings (low-signal and informational)

Showing 60 of 68 findings.

SeverityKindPathDetailPoints
highJs Fs Walk Exfilpackage/dist/chunk-12dkd74n.js45
highJs Fs Walk Exfilpackage/dist/chunk-3q2d4xh5.js45
highJs Fs Walk Exfilpackage/dist/chunk-am5pq8nt.js45
highJs Fs Walk Exfilpackage/dist/chunk-b8d24ts4.js45
highJs Fs Walk Exfilpackage/dist/chunk-gdd0nxj3.js45
highJs Fs Walk Exfilpackage/dist/chunk-hp3b6k4j.js45
highJs Remote Npm Installpackage/dist/chunk-nn1ayzr0.js45
highJs Fs Walk Exfilpackage/dist/chunk-pt667scp.js45
highJs Fs Walk Exfilpackage/dist/chunk-pz313yq8.js45
highJs Fs Walk Exfilpackage/dist/chunk-whttf0jv.js45
highJs Fs Walk Exfilpackage/dist/chunk-y01frwjd.js45
highJs Fs Walk Exfilpackage/dist/chunk-y9b18qce.js45
highNew Lifecycle Script Vs Previouspackage.json40
mediumRemote Payloadpackage/dist/chunk-am5pq8nt.js12
mediumRemote Payloadpackage/dist/chunk-b8d24ts4.js12
mediumRemote Payloadpackage/dist/chunk-hp3b6k4j.js12
mediumRemote Payloadpackage/dist/chunk-pt667scp.js12
mediumRemote Payloadpackage/dist/chunk-pz313yq8.js12
mediumRemote Payloadpackage/dist/chunk-y9b18qce.js12
mediumCredential file accesspackage/dist/chunk-12dkd74n.js10
mediumCredential file accesspackage/dist/chunk-2fv9089a.js10
mediumCredential file accesspackage/dist/chunk-2rnhm735.js10
mediumCredential file accesspackage/dist/chunk-3q2d4xh5.js10
mediumCredential file accesspackage/dist/chunk-4j5qzvpm.js10
mediumCredential file accesspackage/dist/chunk-4wqw507q.js10
mediumCredential file accesspackage/dist/chunk-4zpqh818.js10
mediumCredential file accesspackage/dist/chunk-5zensta2.js10
mediumCredential file accesspackage/dist/chunk-6rqp5q3j.js10
mediumCredential file accesspackage/dist/chunk-6x2asdvn.js10
mediumCredential file accesspackage/dist/chunk-71pxbqa6.js10
mediumCredential file accesspackage/dist/chunk-7jnm7qye.js10
mediumCredential file accesspackage/dist/chunk-ajv5y96r.js10
mediumCredential file accesspackage/dist/chunk-am5pq8nt.js10
mediumCredential file accesspackage/dist/chunk-b8d24ts4.js10
mediumCredential file accesspackage/dist/chunk-bbjzyb52.js10
mediumCredential file accesspackage/dist/chunk-gdd0nxj3.js10
mediumCredential file accesspackage/dist/chunk-hp3b6k4j.js10
mediumCredential file accesspackage/dist/chunk-jke5kjet.js10
mediumCredential file accesspackage/dist/chunk-jyq7q9ya.js10
mediumCredential file accesspackage/dist/chunk-k1qrkf95.js10
mediumCredential file accesspackage/dist/chunk-kt1133hr.js10
mediumCredential file accesspackage/dist/chunk-mjt00k01.js10
mediumCredential file accesspackage/dist/chunk-mv4yh5y6.js10
mediumCredential file accesspackage/dist/chunk-n8hhngdw.js10
mediumCredential file accesspackage/dist/chunk-nfg3jamb.js10
mediumCredential file accesspackage/dist/chunk-pt667scp.js10
mediumCredential file accesspackage/dist/chunk-pz313yq8.js10
mediumCredential file accesspackage/dist/chunk-qz5m1bq8.js10
mediumCredential file accesspackage/dist/chunk-rq2q89pg.js10
mediumCredential file accesspackage/dist/chunk-s633zv7b.js10
mediumCredential file accesspackage/dist/chunk-smaavvtd.js10
mediumCredential file accesspackage/dist/chunk-ve3n24ph.js10
mediumCredential file accesspackage/dist/chunk-vj6gqpka.js10
mediumCredential file accesspackage/dist/chunk-vnmkv183.js10
mediumCredential file accesspackage/dist/chunk-whttf0jv.js10
mediumCredential file accesspackage/dist/chunk-y01frwjd.js10
mediumCredential file accesspackage/dist/chunk-y9b18qce.js10
mediumCredential file accesspackage/dist/chunk-ztnm989w.js10
lowInstall-time lifecycle scriptpackage.json5
lowObfuscation Densitypackage/dist/chunk-4xs38p8q.js0

Manifest

Package metadata

Scripts 16

Sign in to view install / lifecycle script contents.

Dependencies44
  • @ai-sdk/google^1.0.0
  • @anthropic-ai/sdk^0.66.0
  • @codmir/agent-core1.0.2
  • @codmir/agent-runtime0.1.1
  • @codmir/chat-steps1.0.3
  • @codmir/governor1.0.1
  • @codmir/hybrid-reasoning1.0.3
  • @codmir/import-memory0.1.1
  • @codmir/kernel0.1.3
  • @codmir/overseer1.1.5
  • @codmir/reasoning-chain0.1.1
  • @codmir/sdk2.0.0
  • @codmir/sdk-internal1.0.0
  • @codmir/types2.0.4
  • @google/generative-ai^0.24.1
  • axios^1.6.2
  • chalk^5.3.0
  • chokidar^4.0.1
  • clipboardy^4.0.0
  • commander^12.1.0
  • dotenv^16.3.1
  • eventsource^3.0.7
  • form-data^4.0.5
  • fuse.js^7.0.0
  • glob^11.0.0
  • google-auth-library^9.0.0
  • ink5.2.1
  • ink-select-input^6.2.0
  • ink-spinner^5.0.0
  • ink-text-input^6.0.0
  • …and 14 more.