npm · registry.npmjs.org
@comment-io/cli
Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.
Why PkgRadar flagged 0.1.7-alpha.166
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Decode Then Exec | base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/mcp/comment-mcp.mjs |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.1.16-alpha.450 | Low risk | 0 | 2026-06-17 |
0.1.16-alpha.449 | Low risk | 0 | 2026-06-17 |
0.1.15 | Low risk | 0 | 2026-06-17 |
0.1.15-alpha.446 | Low risk | 0 | 2026-06-17 |
0.1.15-alpha.403 | Low risk | 0 | 2026-06-14 |
0.1.15-alpha.382 | Low risk | 0 | 2026-06-14 |
0.1.15-alpha.380 | Low risk | 0 | 2026-06-13 |
0.1.15-alpha.379 | Low risk | 0 | 2026-06-12 |
0.1.15-alpha.377 | Low risk | 0 | 2026-06-12 |
0.1.15-alpha.375 | Low risk | 0 | 2026-06-12 |
0.1.15-alpha.370 | Low risk | 0 | 2026-06-12 |
0.1.15-alpha.369 | Low risk | 0 | 2026-06-12 |
0.1.14 | Low risk | 0 | 2026-06-11 |
0.1.14-alpha.366 | Low risk | 0 | 2026-06-11 |
0.1.14-alpha.365 | Low risk | 0 | 2026-06-11 |
0.1.14-alpha.347 | Low risk | 0 | 2026-06-09 |
0.1.14-alpha.341 | Low risk | 0 | 2026-06-09 |
0.1.13 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.331 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.332 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.330 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.328 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.324 | Low risk | 0 | 2026-06-09 |
0.1.13-alpha.322 | Low risk | 0 | 2026-06-08 |
0.1.13-alpha.314 | Low risk | 0 | 2026-06-06 |
0.1.13-alpha.311 | Low risk | 0 | 2026-06-05 |
0.1.13-alpha.310 | Low risk | 0 | 2026-06-05 |
0.1.13-alpha.308 | Low risk | 0 | 2026-06-04 |
0.1.12 | Low risk | 0 | 2026-06-04 |
0.1.12-alpha.303 | Low risk | 0 | 2026-06-04 |
0.1.11 | Low risk | 0 | 2026-06-04 |
0.1.10 | Low risk | 0 | 2026-06-03 |
0.1.11-alpha.289 | Low risk | 0 | 2026-06-03 |
0.1.10-alpha.286 | Low risk | 0 | 2026-06-03 |
0.1.10-alpha.287 | Low risk | 0 | 2026-06-03 |
0.1.10-alpha.277 | Low risk | 0 | 2026-06-03 |
0.1.10-alpha.275 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.274 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.271 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.272 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.269 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.267 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.266 | Low risk | 0 | 2026-06-02 |
0.1.10-alpha.263 | Low risk | 0 | 2026-06-01 |
0.1.10-alpha.261 | Low risk | 0 | 2026-06-01 |
0.1.10-alpha.259 | Low risk | 0 | 2026-06-01 |
0.1.10-alpha.260 | Low risk | 0 | 2026-06-01 |
0.1.10-alpha.255 | Low risk | 0 | 2026-06-01 |
0.1.9 | Low risk | 0 | 2026-06-01 |
0.1.9-alpha.253 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.251 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.249 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.248 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.247 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.246 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.245 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.243 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.242 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.240 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.239 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.238 | Low risk | 0 | 2026-05-31 |
0.1.9-alpha.237 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.235 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.233 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.231 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.232 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.228 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.227 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.226 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.219 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.218 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.217 | Low risk | 0 | 2026-05-30 |
0.1.9-alpha.216 | Low risk | 0 | 2026-05-30 |
0.1.8-alpha.213 | Low risk | 0 | 2026-05-30 |
0.1.8-alpha.212 | Low risk | 0 | 2026-05-30 |
0.1.8 | Low risk | 0 | 2026-05-30 |
0.1.7-alpha.207 | Low risk | 0 | 2026-05-29 |
0.1.7 | Low risk | 0 | 2026-05-29 |
0.1.7-alpha.166 | Review | 13 | 2026-05-29 |
0.1.7-alpha.168 | Review | 13 | 2026-05-29 |
0.1.7-alpha.157 | Review | 13 | 2026-05-28 |
0.1.7-alpha.159 | Review | 13 | 2026-05-28 |
0.1.7-alpha.154 | Review | 13 | 2026-05-28 |
0.1.7-alpha.155 | Review | 13 | 2026-05-28 |
0.1.7-alpha.151 | Review | 13 | 2026-05-28 |
0.1.7-alpha.152 | Review | 13 | 2026-05-28 |
0.1.7-alpha.148 | Low risk | 0 | 2026-05-28 |
0.1.7-alpha.149 | Low risk | 0 | 2026-05-28 |
0.1.7-alpha.133 | Low risk | 0 | 2026-05-27 |
0.1.7-alpha.135 | Low risk | 0 | 2026-05-27 |
0.1.7-alpha.91 | Low risk | 0 | 2026-05-26 |
0.1.7-alpha.90 | Low risk | 0 | 2026-05-26 |
0.1.7-alpha.89 | Low risk | 0 | 2026-05-26 |
0.1.7-alpha.86 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.85 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.84 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.81 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.82 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.77 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.78 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.69 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.70 | Low risk | 0 | 2026-05-25 |
0.1.7-alpha.48 | Review | 12 | 2026-05-25 |
0.1.7-alpha.45 | Review | 12 | 2026-05-24 |
0.1.7-alpha.44 | Review | 12 | 2026-05-24 |
0.1.7-alpha.43 | Review | 12 | 2026-05-24 |
0.1.7-alpha.42 | Review | 12 | 2026-05-24 |
0.1.7-alpha.39 | Review | 12 | 2026-05-24 |
0.1.7-alpha.40 | Review | 12 | 2026-05-24 |
Block this in CI
pkgradar gate --ecosystem npm @comment-io/[email protected]