Top issues
Detected presence of plaintext credentials within network protocol strings.
Causes risk: web service credentials found
secrets
Problem
Various network communication protocols allow including plaintext authentication credentials. Information such as user names and passwords could be passed through a non-encrypted channel, and therefore intercepted by malicious actors. Credentials are considered secrets, and should be kept encrypted until they are used. This policy control matches the following URI pattern protocol://username:password@domain within any software package component.Prevalence in npm community
1 packages
found in
Top 100
3 packages
found in
Top 1k
103 packages
found in
Top 10k
20397 packages
in community
Next steps
Review the reported matches. If the warning refers to a placeholder credential value, it can be safely ignored.
Top behaviors
Might contain potentially obfuscated code or data.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
21 packages
found in
Top 100
136 packages
found in
Top 1k
1248 packages
found in
Top 10k
390529 packages
in community
Executes files during installation or upon launch.
execution
Prevalence in npm community
No behavior prevalence information at this timeContains URLs that contain basic authentication credentials.
network
Prevalence in npm community
Behavior often found in this community (Common)
2 packages
found in
Top 100
17 packages
found in
Top 1k
205 packages
found in
Top 10k
44587 packages
in community
Contains IP addresses.
network
Prevalence in npm community
Behavior often found in this community (Common)
16 packages
found in
Top 100
80 packages
found in
Top 1k
1432 packages
found in
Top 10k
442524 packages
in community
Contains unusually long strings.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
0 packages
found in
Top 100
0 packages
found in
Top 1k
25 packages
found in
Top 10k
4626 packages
in community
Top vulnerabilities
No vulnerabilities found.