PkgRadar

npm · registry.npmjs.org

@dcl/scene-runtime

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 7.0.6-20240220184109.commit-cf1e4e2

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/sdk6-webworker.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/sdk7-webworker.js
mediumLarge Javascript Payload2795165 bytes · package/dist/sdk6-webworker.dev.js
mediumLarge Javascript Payload2848732 bytes · package/dist/sdk7-webworker.dev.js

Scanned versions

VersionVerdictScoreScanned (UTC)
7.0.6-20240220184109.commit-cf1e4e2Review352026-05-28
7.0.6-20240515153908.commit-adbf9e7Review352026-05-28

Block this in CI

PkgRadar gates @dcl/scene-runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @dcl/[email protected]