PkgRadar

Composer · packagist.org

adrianbj/tracy-debugger

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 5.0.44

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · adrianbj-TracyDebugger-539d9aa/panels/Adminer/adminneo.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · adrianbj-TracyDebugger-539d9aa/panels/Adminer/adminneo.php
mediumRemote Payloadmatched "curl " · adrianbj-TracyDebugger-539d9aa/tracy-2.10.x/tools/create-phar/create-phar.php
mediumRemote Payloadmatched "curl " · adrianbj-TracyDebugger-539d9aa/tracy-2.7.x/tools/create-phar/create-phar.php
mediumRemote Payloadmatched "curl " · adrianbj-TracyDebugger-539d9aa/tracy-2.9.x/tools/create-phar/create-phar.php

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.44Review332026-06-15
5.0.43Review332026-06-15
5.0.42Review332026-06-12
5.0.41Review332026-06-12
5.0.40Review332026-06-11
5.0.39Review332026-06-10
5.0.37Review332026-06-07
5.0.35Review332026-06-03
5.0.34Review362026-05-27
5.0.33Review362026-05-27

Block this in CI

PkgRadar gates adrianbj/tracy-debugger (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer adrianbj/[email protected]