PkgRadar

npm · registry.npmjs.org

@partme.ai/wecom

Obfuscation Density: high encoded/escaped-token density

Why PkgRadar flagged 2026.5.25-3

SeveritySignalEvidence
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunk-4JYCRAWD.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/chunk-5YLF6AF7.js
mediumRemote Payloadmatched "cURL " · package/dist/chunk-NQGXZM44.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.1-2Low risk02026-06-01
2026.6.1-3Low risk02026-06-01
2026.6.1Low risk02026-06-01
2026.6.1-1Low risk02026-06-01
2026.5.25-3Review122026-05-25
2026.5.25-2Review122026-05-24
2026.5.25-1Review122026-05-24
2026.5.2-5.1Review122026-05-24
2026.5.27Review122026-05-24
2026.5.26Review122026-05-24
2026.5.25Review122026-05-24
2026.5.24-3Review122026-05-24
2026.5.24-2Review122026-05-24
2026.5.24Review122026-05-24
2026.5.20Low risk02026-05-24

Related campaigns

Block this in CI

PkgRadar gates @partme.ai/wecom (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @partme.ai/[email protected]