PkgRadar

Package evidence

[email protected]

Credential file access: matched ".azure"

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
145
First published
Apr 2026
Publisher
reasonix

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Publisherreasonix
Artifact bytes8,611,622
Previous version0.48.1
Published2026-05-22T17:14:49.612Z
SHA-25656ccec96b7f55762f214fab0f317802eb16a1741a63d45ccdf9342c794cd7501

Why flagged

What the scanner saw

Credential file access: matched ".azure"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
239Score
0.49.0Version
Status history (2 events)
  1. availableavailable · risk review · score 239 · status available -> available, risk high -> review, score 412 -> 239
  2. newavailable · risk high · score 412 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

reasonix

3 members · evidence strength 74
Repeated static TTPstale

Install Lifecycle Suppresses Failure — prepare="simple-git-hooks || true"

4 members · evidence strength 87

Evidence

Static findings

59 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highCredential file accesspackage/dist/cli/chunk-J2IHQGPQ.jsmatched ".azure"30
highCredential file accesspackage/dist/index.jsmatched ".azure"30
mediumRemote Payloadpackage/dashboard/dist/app.jsmatched "wget "12
mediumRemote Payloadpackage/dist/cli/chunk-FEZK652I.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/cli/chunk-MQWO32ZD.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/chunk-WMTMMSXU.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/chunk-ZWHSHFDP.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/commands-DRHFCYMO.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/index.jshigh encoded/escaped-token density12
mediumLarge Javascript Payloadpackage/dist/cli/chunk-QF32ROX2.js2671491 bytes10
Show all 59 findings (low-signal and informational)
SeverityKindPathDetailPoints
highCredential file accesspackage/dist/cli/chunk-J2IHQGPQ.jsmatched ".azure"30
highCredential file accesspackage/dist/index.jsmatched ".azure"30
mediumRemote Payloadpackage/dashboard/dist/app.jsmatched "wget "12
mediumRemote Payloadpackage/dist/cli/chunk-FEZK652I.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/cli/chunk-MQWO32ZD.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/chunk-WMTMMSXU.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/chunk-ZWHSHFDP.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/cli/commands-DRHFCYMO.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/index.jshigh encoded/escaped-token density12
mediumLarge Javascript Payloadpackage/dist/cli/chunk-QF32ROX2.js2671491 bytes10
lowCredential file accesspackage/dist/cli/chunk-ZWHSHFDP.jsmatched ".ssh"5
lowObfuscationpackage/dist/cli/acp-WFQIC6SO.jsmatched "\\u2026"3
lowObfuscationpackage/dashboard/dist/app.jsmatched "\\x20"3
lowObfuscationpackage/dist/cli/chunk-23ZPCIPR.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-25T6CVUP.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/chunk-3ZZXQ3CZ.jsmatched "\\u2500"3
lowObfuscationpackage/dist/cli/chunk-6OWJV3YW.jsmatched "\\uFF5C"3
lowObfuscationpackage/dist/cli/chunk-7AST3QQ3.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-ASOLXV67.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-AWEULQG6.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/cli/chunk-DFX5ZH5L.jsmatched "\\u2260"3
lowObfuscationpackage/dist/cli/chunk-EQATK2L2.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-GNS7BAT2.jsmatched "\\u21BB"3
lowObfuscationpackage/dist/cli/chunk-HIYTRCSW.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-JNTMOX7G.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/chunk-LGEKVMMV.jsmatched "\\u2192"3
lowObfuscationpackage/dist/cli/chunk-MGTBP7GG.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-MQWO32ZD.jsmatched "\\uD800"3
lowObfuscationpackage/dist/cli/chunk-O5LIHAMP.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-PB3MAFEI.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/chunk-PLHAZOLZ.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-PXBQ6IZ7.jsmatched "\\u25CF"3
lowObfuscationpackage/dist/cli/chunk-Q46B3Z7H.jsmatched "\\x20"3
lowObfuscationpackage/dist/cli/chunk-RRXUIPWG.jsmatched "\\u4e00"3
lowObfuscationpackage/dist/cli/chunk-S4XVGLRW.jsmatched "\\uFEFF"3
lowObfuscationpackage/dist/cli/chunk-SZ5XES2N.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-TAIKVL35.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/chunk-TEDWJKEI.jsmatched "\\u25B8"3
lowObfuscationpackage/dist/cli/chunk-U5XQDCK7.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-W46ZMNKO.jsmatched "\\x1B"3
lowObfuscationpackage/dist/cli/chunk-WMTMMSXU.jsmatched "\\x00"3
lowObfuscationpackage/dist/cli/chunk-YEF7C4XI.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/chunk-ZWHSHFDP.jsmatched "\\uFEFF"3
lowObfuscationpackage/dist/cli/chunk-ZZM6QJ4W.jsmatched "\\u25B8"3
lowObfuscationpackage/dist/cli/commands-DRHFCYMO.jsmatched "\\u2717"3
lowObfuscationpackage/dist/cli/commit-AG5KB4YP.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/desktop-JGL6GORA.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/diff-4Z7ETWZO.jsmatched "\\u2605"3
lowObfuscationpackage/dist/cli/events-VRYXOSKI.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/index.jsmatched "\\xA0"3
lowObfuscationpackage/dist/index.jsmatched "\\u25C7"3
lowObfuscationpackage/dist/cli/mcp-browse-C3GXVMYZ.jsmatched "\\u2026"3
lowObfuscationpackage/dist/cli/mcp-inspect-ZMYUNFDS.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/mcp-LZO4HXFA.jsmatched "\\u25B8"3
lowObfuscationpackage/dist/cli/replay-4TP7ZUMZ.jsmatched "\\u25B0"3
lowObfuscationpackage/dist/cli/run-6MXQYBOE.jsmatched "\\u203A"3
lowObfuscationpackage/dist/cli/server-Z3IMJNNI.jsmatched "\\u2014"3
lowObfuscationpackage/dist/cli/sessions-NXQ5SAV7.jsmatched "\\u2500"3
lowObfuscationpackage/dist/cli/setup-LHZELI6I.jsmatched "\\u7B80"3

Manifest

Package metadata

Scripts14
  • buildtsup && node scripts/copy-dashboard-vendor-css.mjs && node scripts/copy-tree-sitter-grammars.mjs
  • chattsx src/cli/index.ts chat
  • devtsx src/cli/index.ts
  • formatbiome format --write src tests
  • lintbiome check src tests
  • lint:fixbiome check --write src tests
  • preparesimple-git-hooks || true
  • prepublishOnlynpm run lint && npm run typecheck && npm run test && npm run build
  • testvitest run
  • test:coveragevitest run --coverage
  • test:mutationstryker run
  • test:watchvitest
  • typechecktsc --noEmit && tsc --noEmit -p dashboard
  • verifynpm run build && npm run lint && npm run typecheck && npm run test --silent
Dependencies15
  • cli-highlight^2.1.11
  • commander^12.1.0
  • eventsource-parser^3.0.0
  • iconv-lite^0.7.2
  • ignore^7.0.5
  • ink^7.0.2
  • ink-text-input^6.0.0
  • node-html-parser^7.1.0
  • picomatch^4.0.4
  • react^19.2.6
  • string-width^7.2.0
  • undici^8.2.0
  • web-tree-sitter^0.26.9
  • ws^8.20.1
  • zod^4.4.1