PkgRadar

npm · registry.npmjs.org

@kynver-app/runtime

Js Obfuscated Fetch Exec: Hex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection).

Why PkgRadar flagged 0.1.148

SeveritySignalEvidence
highJs Obfuscated Fetch ExecHex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection). · package/dist/cli.js
highJs Obfuscated Fetch ExecHex-decoded literal + network fetch + child-process exec — staged obfuscated-loader / dropper (hides the C2 URL from literal-URL detection). · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.148High risk502026-06-20
0.1.142Low risk02026-06-19
0.1.140Low risk02026-06-16
0.1.139Low risk02026-06-13
0.1.135Low risk02026-06-12
0.1.134Low risk02026-06-12
0.1.132Low risk02026-06-11
0.1.129Low risk02026-06-11
0.1.128Low risk02026-06-11
0.1.123Low risk02026-06-10
0.1.122Low risk02026-06-10
0.1.120Low risk02026-06-10
0.1.118Low risk02026-06-10
0.1.119Low risk02026-06-10
0.1.117Low risk02026-06-10
0.1.116Low risk02026-06-10
0.1.112Low risk02026-06-09
0.1.108Low risk02026-06-09
0.1.106Low risk02026-06-09
0.1.105Low risk02026-06-09
0.1.103Low risk02026-06-08
0.1.102Low risk02026-06-07
0.1.99Low risk02026-06-07
0.1.95Low risk02026-06-06
0.1.93Low risk02026-06-06
0.1.92Low risk02026-06-06
0.1.91Low risk02026-06-06
0.1.90Low risk02026-06-06
0.1.89Low risk02026-06-06
0.1.84Low risk02026-06-06
0.1.82Low risk02026-06-05
0.1.79Low risk02026-06-05
0.1.80Low risk02026-06-05
0.1.76Low risk02026-06-04
0.1.77Low risk02026-06-04
0.1.74Low risk02026-06-03
0.1.73Low risk02026-06-03
0.1.72Low risk02026-06-03
0.1.69Low risk02026-06-03
0.1.66Low risk02026-06-02
0.1.62Low risk02026-06-02
0.1.61Low risk02026-06-02
0.1.60Low risk02026-06-02
0.1.59Low risk02026-06-02
0.1.56Low risk02026-06-01
0.1.51Low risk02026-05-31
0.1.50Low risk02026-05-31
0.1.49Low risk02026-05-31
0.1.48Low risk02026-05-31
0.1.47Low risk02026-05-31
0.1.42Low risk02026-05-30
0.1.38Low risk02026-05-29
0.1.39Low risk02026-05-29
0.1.37Low risk02026-05-29
0.1.34Low risk02026-05-29
0.1.31Low risk02026-05-29
0.1.32Low risk02026-05-29
0.1.28Low risk02026-05-28
0.1.29Low risk02026-05-28
0.1.23Low risk02026-05-27
0.1.22Low risk02026-05-27
0.1.21Low risk02026-05-26
0.1.19Low risk02026-05-25
0.1.17Low risk02026-05-25
0.1.18Low risk02026-05-25
0.1.16Low risk02026-05-25
0.1.11Low risk02026-05-24
0.1.13Low risk02026-05-24

Related campaigns

Block this in CI

PkgRadar gates @kynver-app/runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kynver-app/[email protected]