Composer · packagist.org
xiaosongshu/flv2mp4
Php Base64 Eval Chain: base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload.
Why PkgRadar flagged v1.2.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Php Base64 Eval Chain | base64/gz/hex decode combined with eval/exec/backticks — classic PHP obfuscated payload. · 2723659854-flv2mp4-2801bad/src/SabreAMF/SabreAMF_CallbackServer.php |
| high | Php Shell With Decode | exec / system / shell_exec combined with base64/hex decode. · 2723659854-flv2mp4-2801bad/src/SabreAMF/SabreAMF_CallbackServer.php |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v1.2.1 | High risk | 75 | 2026-06-20 |
v1.2.0 | Low risk | 0 | 2026-06-15 |
v1.1.9 | Low risk | 0 | 2026-06-14 |
v1.1.8 | Low risk | 0 | 2026-06-14 |
v1.1.7 | Low risk | 0 | 2026-06-14 |
v1.1.6 | Low risk | 0 | 2026-06-12 |
v1.1.5 | Low risk | 0 | 2026-06-12 |
v1.1.4 | Low risk | 0 | 2026-06-12 |
v1.1.1 | Low risk | 0 | 2026-06-06 |
v1.0.8 | Low risk | 0 | 2026-06-03 |
v1.0.6 | Low risk | 0 | 2026-06-02 |
v1.0.4 | Low risk | 0 | 2026-05-31 |
v1.0.3 | Low risk | 0 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem composer xiaosongshu/[email protected]