Top issues
Problem
Service access tokens are considered sensitive information that should not be included in released software packages. However, developers frequently release sensitive information alongside their applications to facilitate automated software testing. Testing tokens and keys often proliferate through the software supply chain. Any publicly documented testing keys or service access tokens can safely be ignored. List of such commonly distributed sensitive information is automatically updated and requires no additional user actions.Prevalence in PowerShell Gallery community
1 packages
found in
Top 100
4 packages
found in
Top 1k
5 packages
found in
Top 10k
13 packages
in community
Next steps
Review the commonly shared sensitive information for evidence of inadvertently exposed secrets.
If the tokens were published unintentionally and the software has been made public, you should revoke the tokens and file a security incident.
Top behaviors
Interacts with Microsoft .NET Framework code, types and assemblies.
execution
Prevalence in PowerShell Gallery community
Behavior often found in this community (Common)
100 packages
found in
Top 100
804 packages
found in
Top 1k
6518 packages
found in
Top 10k
11726 packages
in community
Evaluates code dynamically.
execution
Prevalence in PowerShell Gallery community
Behavior often found in this community (Common)
53 packages
found in
Top 100
452 packages
found in
Top 1k
2940 packages
found in
Top 10k
4594 packages
in community
Contains IP addresses.
network
Prevalence in PowerShell Gallery community
Behavior often found in this community (Common)
97 packages
found in
Top 100
693 packages
found in
Top 1k
4437 packages
found in
Top 10k
7330 packages
in community
Tampers with command aliases.
stealth
Prevalence in PowerShell Gallery community
Behavior often found in this community (Common)
7 packages
found in
Top 100
178 packages
found in
Top 1k
987 packages
found in
Top 10k
1613 packages
in community
Contains URLs.
network
Prevalence in PowerShell Gallery community
Behavior often found in this community (Common)
90 packages
found in
Top 100
516 packages
found in
Top 1k
2293 packages
found in
Top 10k
3528 packages
in community
Top vulnerabilities
No vulnerabilities found.