PkgRadar

npm · registry.npmjs.org

@paypal/messaging-components

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 1.84.1

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/js/messaging.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/sandbox/messaging.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/stage/messaging.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/js/versioned/[email protected]
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/sandbox/versioned/[email protected]
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/stage/versioned/[email protected]
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/js/modal.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/sandbox/modal.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/stage/modal.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/js/versioned/[email protected]
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/sandbox/versioned/[email protected]
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/bizcomponents/stage/versioned/[email protected]

Scanned versions

VersionVerdictScoreScanned (UTC)
1.87.0Low risk02026-06-11
1.83.0Low risk02026-06-08
1.86.0Low risk02026-06-08
1.84.1Review152026-05-28
1.85.0Review152026-05-28

Block this in CI

PkgRadar gates @paypal/messaging-components (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @paypal/[email protected]