PkgRadar

npm · registry.npmjs.org

@coalescesoftware/coa

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 7.37.0-alpha.3.h5e37a9481318

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/pystatic/pyodide.asm.js

Scanned versions

VersionVerdictScoreScanned (UTC)
7.38.0-alpha.9.h2ee97c2fec7eLow risk02026-06-13
7.38.0-alpha.5.hbd41839bcf06Low risk02026-06-12
7.37.0-alpha.47.h27d2acb02c5eLow risk02026-06-11
6.0.0Low risk02026-06-10
6.0.2Low risk02026-06-10
6.0.3Low risk02026-06-10
7.37.0-alpha.39.ha75890811d5cLow risk02026-06-10
7.37.0-alpha.45.h135d5e90052dLow risk02026-06-10
7.37.0-alpha.31.h338e6260694aLow risk02026-06-05
7.37.0-alpha.18.he36dc0e8fffbLow risk02026-06-04
7.37.0-alpha.13.hadb326ade802Low risk02026-06-03
7.37.0-alpha.7.h4c6ce2c1bf17Low risk02026-06-02
7.37.0-alpha.3.h5e37a9481318Review202026-05-30
7.35.1Review202026-05-29
7.36.0-alpha.51.h663988b4eb2aReview202026-05-29
7.36.0-alpha.45.h4470ddeef6a6Review622026-05-28
7.36.0-alpha.35.h43572a6d0182Review202026-05-27
7.36.0-alpha.30.hcecb9954bba1Review202026-05-26
7.36.0-alpha.31.h9b16fea28132Review202026-05-26

Block this in CI

PkgRadar gates @coalescesoftware/coa (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @coalescesoftware/[email protected]