registry  /  @benzid.wael/secure-vault  /  0.1.9

@benzid.wael/secure-vault@0.1.9

A secure password management application built with Electron and React

Static Scan Results

scanned 2h ago · by rust-scanner

Static analysis flagged 10 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
One or more suspicious static signals were detected.; previous stored version diff introduced dangerous source

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessCryptoEnvironmentVarsFilesystemShell
Supply chain
HighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 34 file(s), 247 KB of source, external domains: api.example.com

Source & flagged code

4 flagged · loading source
src/electron/services/VaultService.jsView file
295patternName = generic_password severity = medium line = 295 matchedText = console....or);
Medium
Secret Pattern

Package contains a possible secret pattern.

src/electron/services/VaultService.jsView on unpkg · L295
package.jsonView file
Runtime dependency names matching Node built-ins: path
High
Node Builtin Dependency Squat

Package declares a runtime dependency whose name matches a Node built-in module.

package.jsonView on unpkg
bin/commands/env.jsView file
matchType = previous_version_dangerous_delta matchedPackage = @benzid.wael/secure-vault@0.1.7 matchedIdentity = npm:[redacted]:0.1.7 similarity = 0.933 summary = stored previous version shares package body but lacks this dangerous source file
High
Previous Version Dangerous Delta

This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.

bin/commands/env.jsView on unpkg
src/electron/services/recovery/PasswordRecoveryService.jsView file
124patternName = generic_password severity = medium line = 124 matchedText = console....or);
Medium
Secret Pattern

Hardcoded password in src/electron/services/recovery/PasswordRecoveryService.js

src/electron/services/recovery/PasswordRecoveryService.jsView on unpkg · L124

Findings

2 High3 Medium5 Low
HighNode Builtin Dependency Squatpackage.json
HighPrevious Version Dangerous Deltabin/commands/env.js
MediumSecret Patternsrc/electron/services/VaultService.js
MediumEnvironment Vars
MediumSecret Patternsrc/electron/services/recovery/PasswordRecoveryService.js
LowNon Install Lifecycle Scripts
LowScripts Present
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings