PkgRadar

Package evidence

[email protected]

Credential file access: matched "AWS_ACCESS_KEY"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
2,108Mature · −50% score
First published
May 2020
Publisher
GitHub ActionsTrusted automation · −70% score

Effective trust discount applied: 70% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Artifact bytes3,161,843
Previous version0.99.71
Published2026-06-11T14:32:22.869Z
SHA-256918f4d0151b5d181ee5170ae41c559f2e4c1e4066b039948e46f408b5769946c

Why flagged

What the scanner saw

Credential file access: matched "AWS_ACCESS_KEY"

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
6Score
0.99.72Version
Status history (1 event)
  1. newavailable · risk review · score 6 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burstactive

Amazon Web Services

10 members · evidence strength 77
Publisher / release actor burstcandidate

Amazon Web Services

10 members · max score 65

Evidence

Static findings

4 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 4 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowCredential file accesspackage/lib/javascript/node-package.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/lib/javascript/node-project.jsmatched "AWS_ACCESS_KEY"5
lowCredential file accesspackage/lib/javascript/npm-config.jsmatched ".npmrc"5
lowCredential file accesspackage/lib/release/publisher.jsmatched "AWS_ACCESS_KEY"5

Manifest

Package metadata

Scripts36
  • auditnode ./projen.js audit
  • buildnode ./projen.js build
  • bumpnode ./projen.js bump
  • bundle:task-runnernode ./projen.js bundle:task-runner
  • check-licensesnode ./projen.js check-licenses
  • clobbernode ./projen.js clobber
  • compatnode ./projen.js compat
  • compilenode ./projen.js compile
  • defaultnode ./projen.js default
  • devenv:setupnode ./projen.js devenv:setup
  • docgennode ./projen.js docgen
  • ejectnode ./projen.js eject
  • eslintnode ./projen.js eslint
  • integnode ./projen.js integ
  • integ:gonode ./projen.js integ:go
  • integ:javanode ./projen.js integ:java
  • integ:nodenode ./projen.js integ:node
  • integ:pythonnode ./projen.js integ:python
  • packagenode ./projen.js package
  • package-allnode ./projen.js package-all
  • package:gonode ./projen.js package:go
  • package:javanode ./projen.js package:java
  • package:jsnode ./projen.js package:js
  • package:pythonnode ./projen.js package:python
  • post-compilenode ./projen.js post-compile
  • post-upgradenode ./projen.js post-upgrade
  • pre-compilenode ./projen.js pre-compile
  • projennode ./projen.js
  • readme-macrosnode ./projen.js readme-macros
  • releasenode ./projen.js release
  • …and 6 more.
Dependencies15
  • @iarna/toml^2.2.5
  • case^1.6.3
  • chalk^4.1.2
  • comment-json4.2.2
  • constructs^10.5.0
  • conventional-changelog-config-spec^2.1.0
  • fast-glob^3.3.3
  • fast-json-patch^3.1.1
  • ini^2.0.0
  • parse-conflict-json^4.0.0
  • semver^7.8.3
  • shx^0.4.0
  • xmlbuilder2^4.0.3
  • yaml^2.2.2
  • yargs^17.7.2