ベータ Shoulder はベータ版です — 結果が誤っている場合があります。皆さまのフィードバックが次に修正する内容を決定します。 フィードバックを送る

セキュリティアラート

Shoulderのエコシステム分析からのシグナル — 新しいパッケージのスキャン、リスク変化の検出、脆弱性の発見。

アラートは、Shoulderがパッケージを分析し、レビューする価値のあるシグナルを検出したときに生成されます。各アラートは完全な脅威レポートにリンクしています。

npm/@alipay/[email protected] CRITICAL

Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper

  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@salesforce/[email protected] MEDIUM

Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)

npm/@salesforce/[email protected] CRITICAL

Namespace-coordinated publish burst with install-time entry point

  • A dist-tag (e.g. latest) was moved to this version while it was less than 1 hour old — publish-side compromise indicator
npm/@salesforce/[email protected] CRITICAL

Namespace-coordinated publish burst with install-time entry point

  • A dist-tag (e.g. latest) was moved to this version while it was less than 1 hour old — publish-side compromise indicator
npm/@vantaloom/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
npm/@vantaloom/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
npm/@vantaloom/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
npm/@zeniai/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/[email protected] CRITICAL

Package name too similar to opencode-linux-x64-baseline (1.4M weekly downloads)

npm/[email protected] CRITICAL

Package name too similar to opencode-linux-x64-baseline-musl (1.0M weekly downloads)

npm/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Install hook spawns dynamic / forked-detached shell — dropper attribution
  • Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper
  • Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
pypi/[email protected] CRITICAL

Obfuscated payload + credential-harvest capability: javascript-obfuscator-grade output combined with cloud-metadata / bulk-env-sweep / cloud / SSH / browser / wallet credential access

  • matched: verdict_obfuscated_credential_exfil, verdict_runtime_payload_delivery
npm/[email protected] MEDIUM

A dist-tag (e.g. latest) was moved to this version while it was less than 1 hour old — publish-side compromise indicator

  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
npm/[email protected] CRITICAL

Install-time payload delivery: remote fetch + execution during install

  • matched: verdict_payload_delivery_and_execution, verdict_suspicious_install_time_execution