PkgRadar

npm · registry.npmjs.org

@one2x/playwright-core

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 1.57.0-alpha.18

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/lib/vite/traceViewer/assets/defaultSettingsView-B9fHfbV9.js
mediumRemote Payloadmatched "curl " · package/bin/reinstall_chrome_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/bin/reinstall_chrome_stable_mac.sh
mediumRemote Payloadmatched "curl " · package/bin/reinstall_msedge_beta_mac.sh
mediumRemote Payloadmatched "curl " · package/bin/reinstall_msedge_dev_mac.sh
mediumRemote Payloadmatched "curl " · package/bin/reinstall_msedge_stable_mac.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
1.57.0-alpha.18Review282026-05-28
1.57.0-alpha.19Review282026-05-28

Block this in CI

PkgRadar gates @one2x/playwright-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @one2x/[email protected]