PkgRadar

npm · registry.npmjs.org

@communecter/cocolight-api-client

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 1.0.141

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/cocolight-api-client.browser.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.148Low risk02026-06-17
1.0.147Low risk02026-06-16
1.0.146Low risk02026-06-12
1.0.145Low risk02026-06-09
1.0.144Low risk02026-06-09
1.0.142Low risk02026-06-08
1.0.143Low risk02026-06-08
1.0.141Review222026-05-28
1.0.140Review222026-05-28
1.0.139Low risk02026-05-27
1.0.137Low risk02026-05-27
1.0.138Low risk02026-05-27
1.0.135Low risk02026-05-26
1.0.134Low risk02026-05-25
1.0.132Low risk02026-05-25
1.0.133Low risk02026-05-25

Block this in CI

PkgRadar gates @communecter/cocolight-api-client (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @communecter/[email protected]