PkgRadar

npm · registry.npmjs.org

@hardfist/ui

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.1.0

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/storybook-static/sb_dll/storybook_ui_dll.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/storybook-static/vendors~main.1b03e3c9e2ae1e55599f.bundle.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/storybook-static/vendors~main.5abb2040b2d6a230ef94.bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.0Review502026-06-18
1.1.1Review502026-06-18
1.1.2Review502026-06-18
1.2.2Review502026-06-18

Block this in CI

PkgRadar gates @hardfist/ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hardfist/[email protected]