PkgRadar

Composer · packagist.org

maikuolan/cidram

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged v1.29.7

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · CIDRAM-CIDRAM-535b3e5/vault/classes/Maikuolan/Cache.php
highPhp Shell With Decodeexec / system / shell_exec combined with base64/hex decode. · CIDRAM-CIDRAM-535b3e5/vault/classes/Maikuolan/Cache.php
mediumRemote Payloadmatched "raw.githubusercontent.com" · CIDRAM-CIDRAM-535b3e5/vault/frontend.php

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.29.7Review262026-06-10
v2.17.4Review262026-06-10
v3.12.0Review272026-06-10
v4.2.0Review322026-06-10

Block this in CI

PkgRadar gates maikuolan/cidram (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer maikuolan/[email protected]