AIdhirajSingh/cr-exfil-test-fixture
Scored 0/100 (Malicious). What the code does: Code references credential paths (SSH keys, cloud credentials, .npmrc, or bulk env read); Network/shell activity wired into an install-time hook (runs on install, before import); 2 code/behavior finding(s) reported by the read model. This repository is a self-declared security test fixture designed to validate sandbox containment. The flagged behaviors (postinstall network activity and credential access) are explicitly documented in the README and align with the project's stated purpose as a synthetic test case.
Neutral
package.json contains a postinstall script executing 'node beacon.js'. This is consistent with the README's stated intent to test sandbox interception during installation.
beacon.js attempts to read ~/.aws/credentials. This is flagged as a test-fixture context, consistent with the repo's declared purpose of testing sandbox containment.
Owner account is 10 months old with only 2 public repositories and no stars, indicating a lack of community reputation.