PkgRadar

npm · registry.npmjs.org

@dahawa/hawa-code

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 1.36.3

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/hawa.js
mediumLarge Javascript Payload5986892 bytes · package/cli.js
mediumLarge Javascript Payload5141103 bytes · package/hands.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.38.9Low risk02026-06-12
1.38.8Low risk02026-06-12
1.38.7Low risk02026-06-12
1.38.6Low risk02026-06-12
1.38.5Low risk02026-06-12
1.38.4Low risk02026-06-12
1.38.3Low risk02026-06-12
1.38.2Low risk02026-06-08
1.38.1Low risk02026-06-08
1.38.0Low risk02026-06-08
1.37.4Low risk02026-06-07
1.37.3Low risk02026-06-03
1.37.1Low risk02026-06-02
1.37.2Low risk02026-06-02
1.37.0Low risk02026-06-02
1.36.3Review202026-05-25
1.36.2Review202026-05-25
1.36.1Review202026-05-24
1.35.5Review102026-05-24
1.36.0Review202026-05-24

Block this in CI

PkgRadar gates @dahawa/hawa-code (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dahawa/[email protected]