PkgRadar

Maven · repo1.maven.org

com.volcengine:volcengine-java-sdk-llmshield

Java Base64 Combo: Base64.decode combined with network / process / defineClass — classic obfuscated payload.

Why PkgRadar flagged 2.0.13

SeveritySignalEvidence
highJava Base64 ComboBase64.decode combined with network / process / defineClass — classic obfuscated payload. · com/volcengine/llmshield/aicc/Utils.java
mediumRemote Payloadmatched "cUrl " · com/volcengine/llmshield/AiccModuleConfResult.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.13High risk422026-06-12

Block this in CI

PkgRadar gates com.volcengine:volcengine-java-sdk-llmshield (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.volcengine:[email protected]