PkgRadar

Composer · packagist.org

aws/aws-sdk-php

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 3.385.0

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · aws-aws-sdk-php-994e340/src/EndpointV2/Bdd/BddNodeDecoder.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · aws-aws-sdk-php-994e340/src/EndpointV2/Bdd/BddNodeDecoder.php
mediumRemote Payloadmatched "curl " · aws-aws-sdk-php-994e340/src/ClientResolver.php
mediumRemote Payloadmatched "cURL " · aws-aws-sdk-php-994e340/src/Credentials/InstanceProfileProvider.php
mediumRemote Payloadmatched "cURL " · aws-aws-sdk-php-994e340/src/RetryMiddlewareV2.php

Scanned versions

VersionVerdictScoreScanned (UTC)
3.385.0Review572026-06-17
3.384.11Review572026-06-16
3.384.10Review572026-06-15
3.384.7Review572026-06-10
3.384.6Review572026-06-09
3.384.3Review572026-06-04
3.383.0Review632026-05-28
3.382.2Review602026-05-27

Block this in CI

PkgRadar gates aws/aws-sdk-php (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer aws/[email protected]