npm · registry.npmjs.org
@iicp/client
Js Obfuscated Fetch Exec: Hex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection).
Why PkgRadar flagged 0.7.63
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Obfuscated Fetch Exec | Hex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection). · package/dist/cli.js |
| medium | Tls Verification Disabled | matched "NODE_TLS_REJECT_UNAUTHORIZED=0" · package/dist/client.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.7.63 | High risk | 57 | 2026-06-20 |
0.7.62 | Low risk | 0 | 2026-06-13 |
0.7.61 | Low risk | 0 | 2026-06-13 |
0.7.60 | Low risk | 0 | 2026-06-13 |
0.7.59 | Low risk | 0 | 2026-06-12 |
0.7.57 | Low risk | 0 | 2026-06-12 |
0.7.58 | Low risk | 0 | 2026-06-12 |
0.7.56 | Low risk | 0 | 2026-06-12 |
0.7.54 | Low risk | 0 | 2026-06-11 |
0.7.51 | Low risk | 0 | 2026-06-10 |
0.7.50 | Low risk | 0 | 2026-06-10 |
0.7.48 | Low risk | 0 | 2026-06-10 |
0.7.46 | Low risk | 0 | 2026-06-08 |
0.7.45 | Low risk | 0 | 2026-06-08 |
0.7.44 | Low risk | 0 | 2026-06-08 |
0.7.43 | Low risk | 0 | 2026-06-08 |
0.7.42 | Low risk | 0 | 2026-06-08 |
0.7.40 | Low risk | 0 | 2026-06-07 |
0.7.39 | Low risk | 0 | 2026-06-07 |
0.7.38 | Low risk | 0 | 2026-06-07 |
0.7.37 | Low risk | 0 | 2026-06-05 |
0.7.36 | Low risk | 0 | 2026-06-03 |
0.7.35 | Low risk | 0 | 2026-06-03 |
0.7.32 | Low risk | 0 | 2026-06-03 |
0.7.12 | Low risk | 0 | 2026-05-30 |
0.7.11 | Low risk | 0 | 2026-05-29 |
0.7.10 | Low risk | 0 | 2026-05-29 |
0.7.8 | Low risk | 0 | 2026-05-29 |
0.7.6 | Low risk | 0 | 2026-05-29 |
0.7.7 | Low risk | 0 | 2026-05-29 |
0.7.3 | Low risk | 0 | 2026-05-29 |
0.7.5 | Low risk | 0 | 2026-05-29 |
0.5.6 | Low risk | 0 | 2026-05-27 |
0.5.7 | Low risk | 0 | 2026-05-27 |
0.5.3 | Low risk | 0 | 2026-05-27 |
0.5.4 | Low risk | 0 | 2026-05-27 |
0.2.0 | Low risk | 0 | 2026-05-25 |
Related campaigns
Block this in CI
pkgradar gate --ecosystem npm @iicp/[email protected]