PkgRadar

npm · registry.npmjs.org

@feedmepos/mf-menu

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 0.32.51-dev

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/App-DJ_boY0P.js
highRemote Dependency Specdependencies.@feedmepos/mf-inventory-portal="https://registry.npmjs.org/@feedmepos/mf-inventory-portal/-/mf-inventory-portal-0.0.19-dev.6.tgz" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.32.51-devHigh risk262026-06-12
0.32.50-dev.1High risk262026-06-10
0.32.49Review262026-05-29
0.32.48Review462026-05-28
0.32.49-devReview462026-05-28

Block this in CI

PkgRadar gates @feedmepos/mf-menu (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @feedmepos/[email protected]