PkgRadar

Composer · packagist.org

tokushima/ebi

Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.

Why PkgRadar flagged 4.2.10

SeveritySignalEvidence
highPhp Base64 Eval Chainbase64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · tokushima-ebi-43ab1dc/lib/ebi/Util.php
highPhp Backtick With DecodeBacktick shell-out combined with base64/hex decode. · tokushima-ebi-43ab1dc/lib/ebi/Util.php
mediumComposer Abandoned PackagePackagist marked this package abandoned — maintainer signaled it should not be used.
mediumRemote Payloadmatched "cURL " · tokushima-ebi-43ab1dc/lib/ebi/HttpClient.php

Scanned versions

VersionVerdictScoreScanned (UTC)
4.2.10High risk1022026-06-07
4.2.8High risk872026-06-01
4.2.9High risk1022026-05-30

Block this in CI

PkgRadar gates tokushima/ebi (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem composer tokushima/[email protected]