Top issues
Detected presence of web service access tokens.
Causes risk: web service credentials found
secrets
Problem
Software as a Service (SaaS) platforms expose programmable interfaces to their authenticated users. These web services enable action automation and secure exchange of information. For authorization, web service users provide a unique token that confirms their access rights. These tokens are considered secrets. They should never be included in a software release package, even if they are obfuscated by encryption on the client-side.Prevalence in npm community
0 packages
found in
Top 100
1 packages
found in
Top 1k
21 packages
found in
Top 10k
8821 packages
in community
Next steps
You should securely store web service access tokens, and fully automate their management and periodic rotation.
If tokens were published unintentionally and the software has been made public, you should revoke exposed tokens and file a security incident.
Examples of service tokens that may have been detected include AWS, Facebook, JWT, SWT, Slack and others.
Top behaviors
Might contain potentially obfuscated code or data.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
21 packages
found in
Top 100
136 packages
found in
Top 1k
1248 packages
found in
Top 10k
390529 packages
in community
Encodes data using the Base64 algorithm.
packer
Prevalence in npm community
Behavior often found in this community (Common)
7 packages
found in
Top 100
61 packages
found in
Top 1k
956 packages
found in
Top 10k
319930 packages
in community
Executes files during installation or upon launch.
execution
Prevalence in npm community
No behavior prevalence information at this timeContains IP addresses.
network
Prevalence in npm community
Behavior often found in this community (Common)
16 packages
found in
Top 100
80 packages
found in
Top 1k
1432 packages
found in
Top 10k
442524 packages
in community
Contains unusually long strings.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
0 packages
found in
Top 100
0 packages
found in
Top 1k
25 packages
found in
Top 10k
4626 packages
in community
Top vulnerabilities
No vulnerabilities found.