PkgRadar

npm · registry.npmjs.org

@orbit-software/sdk

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.94.2

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/umd_react/sdk_react.umd.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/esm/sdk.umd.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/umd/sdk.umd.js
mediumRemote Dependency Specdependencies.@orbit-software/analytics="github:orbit-software/games-launcher#analytics-v0.1.1&path:/packages/analytics" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
1.94.2High risk312026-06-10
1.94.1High risk312026-06-10
1.94.0Review62026-06-01

Block this in CI

PkgRadar gates @orbit-software/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @orbit-software/[email protected]