बीटा Shoulder बीटा में है — परिणाम कभी-कभी गलत हो सकते हैं। आपकी प्रतिक्रिया तय करती है कि हम आगे क्या ठीक करें। प्रतिक्रिया साझा करें

सुरक्षा अलर्ट

Shoulder के इकोसिस्टम विश्लेषण से सिग्नल — नए पैकेज स्कैन किए, जोखिम परिवर्तन पहचाने, और कमज़ोरियां उजागर हुईं।

अलर्ट तब उत्पन्न होते हैं जब Shoulder किसी पैकेज का विश्लेषण करता है और समीक्षा के योग्य सिग्नल पहचानता है। प्रत्येक अलर्ट पूर्ण खतरा ब्रीफिंग से जुड़ता है।

npm/@camstack/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Dynamic eval + network + shell exec — dropper trio (arbitrary code execution, exfiltration channel, OS access)
  • Obfuscated shell execution — concealment pattern
  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@camstack/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@knapsack/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

npm/@knapsack/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Dynamic eval + network access BOTH appeared in this version — hijack shape (payload-introduction signature; neither cap was present in the trust-anchor baseline)
  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@mjasnikovs/[email protected] HIGH

Payload delivery from suspicious source: IOC URL + execution capability

  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
npm/@ramonclaudio/[email protected] CRITICAL

Bulk env-var sweep + shell exec at runtime — credential-stealer

  • A dist-tag (e.g. latest) was moved to this version while it was less than 1 hour old — publish-side compromise indicator
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Obfuscated shell execution — concealment pattern
npm/@reddb-io/[email protected] CRITICAL

Install-time payload delivery: remote fetch + execution during install

  • matched: verdict_payload_delivery_and_execution, verdict_suspicious_install_download_source, verdict_runtime_payload_delivery, verdict_suspicious_install_time_execution
npm/@reddb-io/[email protected] CRITICAL

Install-time suspicious download: evidence contains raw IP, tunnel service, or paste site URL

  • matched: verdict_suspicious_install_download_source, verdict_runtime_payload_delivery
npm/@vellumai/[email protected] MEDIUM

Dynamic / forked-detached shell paired with code obfuscation — runtime dropper attribution (no install hook required)

npm/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Install hook spawns dynamic / forked-detached shell — dropper attribution
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
npm/[email protected] MEDIUM

npm main entrypoint contains side-effecting code AFTER its last module.exports / export default — runs silently on require() and reaches a dangerous capability (install-hook bypass)

npm/[email protected] CRITICAL

Suspicious install-time execution: 2+ suspicious signals during install

  • CLI bin entry points at the same file as a lifecycle script (preinstall/install/postinstall/prepare) — [email protected] dual-trigger
  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Install hook spawns dynamic / forked-detached shell — dropper attribution
  • Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence
npm/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

pypi/[email protected] CRITICAL

Bulk env-var sweep + shell exec at runtime — credential-stealer

  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
pypi/[email protected] MEDIUM

Dynamic / forked-detached shell paired with code obfuscation — runtime dropper attribution (no install hook required)

  • Dynamic eval + network + shell exec — dropper trio (arbitrary code execution, exfiltration channel, OS access)
  • Obfuscated shell execution — concealment pattern
  • Dynamic code evaluation with network access — potential code injection or exfiltration