PkgRadar

Package evidence

[email protected]

Credential file access: matched ".ssh"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publisherumyunsang
Artifact bytes9,905,285
Previous version0.0.0-namecheck
Published2026-05-07T15:51:34.925Z
SHA-2566fff4257b4f58d8bd23f3ce55c13e7d4772e9116a39a324d500a3035592c9662

Why flagged

What the scanner saw

Credential file access: matched ".ssh"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

not present

status
Last checked
noneRisk
Score
0.1.0Version

Latest scanner note: [email protected] not present in registry metadata

Status history (2 events)
  1. availablenot_present · risk none · score · [email protected] not present in registry metadata
  2. newavailable · risk high · score 1452 · status changed

Related candidates

Linked campaigns and clusters

Repeated static TTPstale

Credential file access — matched "kubeconfig"

19 members · evidence strength 90
Publisher / release actor burststale

umyunsang

2 members · evidence strength 64

Evidence

Static findings

142 static · 0 from release diff · showing high-signal first.

Showing 30 of 56 findings.

SeverityKindPathDetailPoints
highCredential file accesspackage/src/ummaya/safety/_patterns.pymatched ".ssh"30
highCredential file accesspackage/tui/src/utils/autoUpdater.tsmatched ".npmrc"30
highCredential file accesspackage/tui/src/utils/aws.tsmatched ".aws"30
highCredential file accesspackage/tui/src/tools/BashTool/bashPermissions.tsmatched "KUBECONFIG"30
highCredential file accesspackage/tui/src/tools/BashTool/bashSecurity.tsmatched ".ssh"30
highCredential file accesspackage/src/ummaya/llm/_cc_reference/client.tsmatched ".azure"30
highCredential file accesspackage/tui/src/utils/permissions/dangerousPatterns.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/env.tsmatched ".AWS"30
highCredential file accesspackage/tui/src/utils/envUtils.tsmatched ".AWS"30
highCredential file accesspackage/tui/src/utils/plugins/fetchTelemetry.tsmatched ".azure"30
highCredential file accesspackage/tui/src/utils/permissions/filesystem.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/fsOperations.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/ide.tsmatched ".npmrc"30
highCredential file accesspackage/tui/src/utils/plugins/marketplaceManager.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/deepLink/parseDeepLink.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/memdir/paths.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/pathValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/permissions/pathValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/powershellPermissions.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/WebFetchTool/preapproved.tsmatched ".aws"30
highCredential file accesspackage/tui/src/tools/BashTool/prompt.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/readOnlyValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/sandbox/sandbox-adapter.tsmatched ".aws"30
highCredential file accesspackage/tui/src/utils/plugins/schemas.tsmatched ".azure"30
highDNS / OAST exfiltrationpackage/tui/src/utils/hooks/ssrfGuard.tsmatched "dns.lookup"30
highCredential file accesspackage/tui/src/utils/subprocessEnv.tsmatched "GITHUB_TOKEN"30
highCredential file accesspackage/tui/src/memdir/teamMemPaths.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/settings/types.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/components/TrustDialog/utils.tsmatched ".aws"30
mediumRemote Payloadpackage/src/ummaya/settings.pymatched "raw.githubusercontent.com"12
Show all 142 findings (low-signal and informational)

Showing 60 of 142 findings.

SeverityKindPathDetailPoints
highCredential file accesspackage/src/ummaya/safety/_patterns.pymatched ".ssh"30
highCredential file accesspackage/tui/src/utils/autoUpdater.tsmatched ".npmrc"30
highCredential file accesspackage/tui/src/utils/aws.tsmatched ".aws"30
highCredential file accesspackage/tui/src/tools/BashTool/bashPermissions.tsmatched "KUBECONFIG"30
highCredential file accesspackage/tui/src/tools/BashTool/bashSecurity.tsmatched ".ssh"30
highCredential file accesspackage/src/ummaya/llm/_cc_reference/client.tsmatched ".azure"30
highCredential file accesspackage/tui/src/utils/permissions/dangerousPatterns.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/env.tsmatched ".AWS"30
highCredential file accesspackage/tui/src/utils/envUtils.tsmatched ".AWS"30
highCredential file accesspackage/tui/src/utils/plugins/fetchTelemetry.tsmatched ".azure"30
highCredential file accesspackage/tui/src/utils/permissions/filesystem.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/fsOperations.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/ide.tsmatched ".npmrc"30
highCredential file accesspackage/tui/src/utils/plugins/marketplaceManager.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/deepLink/parseDeepLink.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/memdir/paths.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/pathValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/permissions/pathValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/powershellPermissions.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/WebFetchTool/preapproved.tsmatched ".aws"30
highCredential file accesspackage/tui/src/tools/BashTool/prompt.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/tools/PowerShellTool/readOnlyValidation.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/sandbox/sandbox-adapter.tsmatched ".aws"30
highCredential file accesspackage/tui/src/utils/plugins/schemas.tsmatched ".azure"30
highDNS / OAST exfiltrationpackage/tui/src/utils/hooks/ssrfGuard.tsmatched "dns.lookup"30
highCredential file accesspackage/tui/src/utils/subprocessEnv.tsmatched "GITHUB_TOKEN"30
highCredential file accesspackage/tui/src/memdir/teamMemPaths.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/utils/settings/types.tsmatched ".ssh"30
highCredential file accesspackage/tui/src/components/TrustDialog/utils.tsmatched ".aws"30
mediumRemote Payloadpackage/src/ummaya/settings.pymatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/src/ummaya/tools/mohw/welfare_eligibility_search.pymatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/bash/ast.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/tools/BashTool/bashPermissions.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/tools/BashTool/bashSecurity.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/skills/bundled/batch.tsmatched "curl "12
mediumRemote Payloadpackage/src/ummaya/llm/_cc_reference/client.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/bash/commands.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/powershell/dangerousCmdlets.tsmatched "invoke-webrequest"12
mediumRemote Payloadpackage/tui/src/utils/permissions/dangerousPatterns.tsmatched "wget "12
mediumRemote Payloadpackage/tui/src/utils/plugins/fetchTelemetry.tsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/tui/src/tools/shared/gitOperationTracking.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/bash/heredoc.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/commands/init-verifiers.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/plugins/installCounts.tsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/tui/src/utils/powershell/parser.tsmatched "Invoke-WebRequest"12
mediumRemote Payloadpackage/tui/src/tools/PowerShellTool/pathValidation.tsmatched "Invoke-WebRequest"12
mediumRemote Payloadpackage/src/ummaya/llm/_cc_reference/permissions.tsmatched "iwr "12
mediumRemote Payloadpackage/tui/src/utils/permissions/permissions.tsmatched "iwr "12
mediumRemote Payloadpackage/tui/src/commands/plugin-init.tsmatched "github.com/ummaya-plugin-store/ummaya-plugin-${opts.name}/releases/download"12
mediumRemote Payloadpackage/tui/src/tools/PowerShellTool/powershellPermissions.tsmatched "invoke-webrequest"12
mediumRemote Payloadpackage/tui/src/utils/shell/powershellProvider.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/tools/PowerShellTool/powershellSecurity.tsmatched "IWR "12
mediumRemote Payloadpackage/tui/src/cli/print.tsmatched "cUrl "12
mediumRemote Payloadpackage/tui/src/tools/RemoteTriggerTool/prompt.tsmatched "curl "12
mediumRemote Payloadpackage/tui/src/utils/releaseNotes.tsmatched "raw.githubusercontent.com"12
mediumRemote Payloadpackage/tui/src/tools/BashTool/shouldUseSandbox.tsmatched "curl "12
lowObfuscationpackage/src/ummaya/safety/_patterns.pymatched "\\uc774"3
lowObfuscationpackage/src/ummaya/permissions/canonical_json.pymatched "\\u0000"3
lowObfuscationpackage/src/ummaya/engine/tokens.pymatched "\\uac00"3
lowObfuscationpackage/src/ummaya/tools/mohw/welfare_eligibility_search.pymatched "\\ufffd"3

Manifest

Package metadata

Scripts11
  • diff:upstreambun run scripts/diff-upstream.ts
  • gen:ipcbun run scripts/gen-ipc-types.ts
  • gen:pipa-hashbun run scripts/gen-pipa-hash.ts
  • probe:tool-registrybun src/probes/toolRegistryProbe.tsx
  • testbun test tests/adr-precheck.test.ts tests/entrypoints tests/hooks tests/i18n tests/ink tests/ipc tests/memdir tests/permissions tests/primitive tests/store tests/theme tests/unit
  • test:allbun test
  • test:soakbun test --timeout 600000 tests/soak
  • tuibun run src/entrypoints/cli.tsx
  • tui:smokebun run scripts/tui-smoke.ts
  • typechecktsc --noEmit -p tsconfig.typecheck.json
  • typecheck:fulltsc --noEmit
Dependencies68
  • @alcalzone/ansi-tokenize^0.3.0
  • @anthropic-ai/claude-agent-sdk^0.2.119
  • @anthropic-ai/mcpb^2.1.2
  • @anthropic-ai/sandbox-runtime^0.0.49
  • @anthropic-ai/sdk^0.37.0
  • @aws-sdk/client-bedrock-runtime^3.1036.0
  • @commander-js/extra-typings^12.1.0
  • @growthbook/growthbook^1.6.5
  • @grpc/grpc-js^1.14.3
  • @inkjs/ui^2.0.0
  • @modelcontextprotocol/sdk^1.29.0
  • @opentelemetry/api^1.9.1
  • @opentelemetry/api-logs^0.215.0
  • @opentelemetry/core^2.7.0
  • @opentelemetry/exporter-logs-otlp-grpc^0.216.0
  • @opentelemetry/exporter-logs-otlp-http^0.216.0
  • @opentelemetry/exporter-logs-otlp-proto^0.216.0
  • @opentelemetry/exporter-metrics-otlp-grpc^0.216.0
  • @opentelemetry/exporter-metrics-otlp-http^0.216.0
  • @opentelemetry/exporter-metrics-otlp-proto^0.216.0
  • @opentelemetry/exporter-trace-otlp-grpc^0.216.0
  • @opentelemetry/exporter-trace-otlp-http^0.216.0
  • @opentelemetry/exporter-trace-otlp-proto^0.216.0
  • @opentelemetry/resources^2.7.0
  • @opentelemetry/sdk-logs^0.215.0
  • @opentelemetry/sdk-metrics^2.7.0
  • @opentelemetry/sdk-trace-base^2.7.0
  • @opentelemetry/semantic-conventions^1.40.0
  • @pdf-lib/fontkit^1.1.1
  • ajv^8.18.0
  • …and 38 more.