npm · registry.npmjs.org
@replit/replbox
Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.
Why PkgRadar flagged 2.17.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/coffeescript.js |
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/html.js |
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/javascript.js |
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/roy.js |
| high | Js Split Join Obfuscation | Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/web_project.js |
| medium | Remote Dependency Spec | devDependencies.apl="git+https://github.com/ngn/apl.git#cc314fe3be5f2d018d556b7e91916711e46d265e" · package.json |
| medium | Remote Dependency Spec | devDependencies.biwascheme="git+https://github.com/masad-frost/biwascheme.git#3c0d5a67cd1af696c69ab7fb085b2f42c8b0586c" · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
2.17.0 | High risk | 33 | 2026-06-20 |
2.18.0 | High risk | 33 | 2026-06-20 |
2.19.0 | High risk | 33 | 2026-06-20 |
2.20.0 | High risk | 33 | 2026-06-20 |
Block this in CI
pkgradar gate --ecosystem npm @replit/[email protected]