PkgRadar

Composer · packagist.org

mgamadeus/ddd

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 2.38.0

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · mgamadeus-ddd-ab9f399/src/Domain/Base/Entities/MessageHandlers/AppMessage.php
highPhp Shell With Decodeexec / system / shell_exec combined with base64/hex decode. · mgamadeus-ddd-ab9f399/src/Domain/Base/Entities/MessageHandlers/AppMessage.php
mediumRemote Payloadmatched "cUrl " · mgamadeus-ddd-ab9f399/src/Domain/Common/Entities/MediaItems/GenericMediaItem.php
mediumRemote Payloadmatched "cUrl " · mgamadeus-ddd-ab9f399/src/Domain/Common/Entities/MediaItems/MediaItemContentTrait.php

Scanned versions

VersionVerdictScoreScanned (UTC)
2.38.0High risk492026-06-16
2.34.0High risk492026-06-14
2.35.0High risk492026-06-14
2.31.0High risk492026-06-10
2.30.0High risk492026-06-10
2.28.0High risk492026-06-03
2.27.0High risk492026-06-02
2.25.0High risk492026-05-30

Block this in CI

PkgRadar gates mgamadeus/ddd (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer mgamadeus/[email protected]