PkgRadar

npm · registry.npmjs.org

@hed-hog/operations

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 0.0.354

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/operations.service.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/src/operations.service.ts

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.365Low risk02026-06-12
0.0.364Low risk02026-06-06
0.0.361Low risk02026-06-01
0.0.358Low risk02026-05-31
0.0.354Review352026-05-28
0.0.355Review502026-05-28
0.0.351Low risk02026-05-26
0.0.353Low risk02026-05-26

Block this in CI

PkgRadar gates @hed-hog/operations (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @hed-hog/[email protected]