PkgRadar

npm · registry.npmjs.org

@box/box-ai-content-answers

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.47.0

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/chunks/markdown.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.48.5Low risk02026-06-12
1.48.4Low risk02026-06-12
1.48.3Low risk02026-06-12
1.48.2Low risk02026-06-11
1.48.0Low risk02026-06-11
1.48.1Low risk02026-06-11
1.47.13Low risk02026-06-09
1.47.11Low risk02026-06-09
1.47.12Low risk02026-06-09
1.47.10Low risk02026-06-08
1.47.9Low risk02026-06-03
1.47.8Low risk02026-06-03
1.47.7Low risk02026-06-03
1.47.6Low risk02026-06-02
1.47.5Low risk02026-06-02
1.47.4Low risk02026-06-02
1.47.3Low risk02026-06-01
1.47.2Low risk02026-06-01
1.47.1Low risk02026-06-01
1.47.0Review202026-05-29
1.46.24Review202026-05-28
1.46.23Review202026-05-28
1.46.22Review202026-05-28
1.46.21Low risk02026-05-28
1.46.20Low risk02026-05-27
1.46.18Low risk02026-05-27
1.46.19Low risk02026-05-27

Block this in CI

PkgRadar gates @box/box-ai-content-answers (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @box/[email protected]