PkgRadar

npm · registry.npmjs.org

@cloudbase/cloudbase-mcp

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 2.20.2

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/508.index.cjs
mediumLarge Javascript Payload4325535 bytes · package/dist/cli.cjs
mediumLarge Javascript Payload9666719 bytes · package/dist/index.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.22.0Low risk02026-06-10
2.21.1-beta.2Low risk02026-06-10
2.21.1-beta.1Low risk02026-06-08
2.21.1Low risk02026-06-05
2.21.1-beta.0Low risk02026-06-05
2.21.0Low risk02026-06-04
2.20.2Review192026-05-28
2.20.1Review62026-05-25
2.20.0Review442026-05-25
2.20.0-beta.0Review442026-05-25

Block this in CI

PkgRadar gates @cloudbase/cloudbase-mcp (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @cloudbase/[email protected]