PkgRadar

npm · registry.npmjs.org

@esome-dev/ppms

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.0.0-alpha.17

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/activate.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/checkin.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/signin.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/signup.js
mediumRemote Payloadmatched "curl " · package/installer/install.sh
mediumRemote Payloadmatched "curl " · package/installer/upgrade.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.0-alpha.17Review372026-06-11
1.0.0-alpha.18Review372026-06-11
1.0.4Review372026-06-11
1.2.121Low risk02026-06-11
1.2.118Low risk02026-06-08
1.2.119Low risk02026-06-08
1.2.120Low risk02026-06-08
1.2.117Low risk02026-06-08

Block this in CI

PkgRadar gates @esome-dev/ppms (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @esome-dev/[email protected]