ベータ Shoulder はベータ版です — 結果が誤っている場合があります。皆さまのフィードバックが次に修正する内容を決定します。 フィードバックを送る

セキュリティアラート

Shoulderのエコシステム分析からのシグナル — 新しいパッケージのスキャン、リスク変化の検出、脆弱性の発見。

アラートは、Shoulderがパッケージを分析し、レビューする価値のあるシグナルを検出したときに生成されます。各アラートは完全な脅威レポートにリンクしています。

npm/@angriff36/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Dynamic eval + network + shell exec — dropper trio (arbitrary code execution, exfiltration channel, OS access)
  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@direxio/[email protected] CRITICAL

Install-time payload delivery: remote fetch + execution during install

  • matched: verdict_payload_delivery_and_execution, verdict_suspicious_install_time_execution
npm/@h-rig/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Sensitive file access with network egress — credential exfiltration pattern
npm/@hasna/[email protected] CRITICAL

Bulk env-var sweep + shell exec at runtime — credential-stealer

  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + credential reads + network to suspicious target (raw IP / paste site / tunnel) — credential stealer; not a legitimate cloud SDK
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@memberjunction/[email protected] CRITICAL

Newly-introduced runtime execution surface (eval / shell / network) on a package published inside a coordinated burst of uninspectable ballooned bundles by the same maintainer account - stage-1 dropper precursor, failing closed

  • Burst publisher with new account
npm/@sentry/[email protected] CRITICAL

Import-time bundle the scanner could not fully inspect (streaming fallback on an oversized bundle) whose tarball ballooned sharply vs its last clean release and which carries a runtime execution / exfil surface (eval / shell / network) - uninspectable runtime payload, anomalous for this lineage, failing closed

  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
npm/@sigmashake/[email protected] CRITICAL

Install-time payload delivery: remote fetch + execution during install

  • matched: verdict_payload_delivery_and_execution, verdict_suspicious_install_time_execution
pypi/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Raw socket usage paired with credential reads — possible TCP exfil bypass
pypi/[email protected] MEDIUM

Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence

  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
npm/[email protected] CRITICAL

Install hook spawns dynamic / forked-detached shell — dropper attribution

  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)