PkgRadar

npm · registry.npmjs.org

@sentio/runtime

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 3.9.0-rc.12

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/lib/chunk-EXIISBRV.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.0.0-rc.3Low risk02026-06-11
4.0.0-rc.2Low risk02026-06-10
2.62.0-rc.16Low risk02026-06-10
2.62.0-rc.13Low risk02026-06-10
2.62.0-rc.14Low risk02026-06-10
2.63.1Low risk02026-06-05
3.8.1Low risk02026-06-05
3.8.1-rc3.1Low risk02026-06-04
2.63.1-rc2.1Low risk02026-06-04
3.8.0Low risk02026-06-03
2.63.0Low risk02026-06-03
3.8.0-rc3.4Low risk02026-06-03
2.63.0-rc2.3Low risk02026-06-03
2.63.0-rc2.1Low risk02026-06-02
2.63.0-rc2.2Low risk02026-06-02
3.8.0-rc3.3Low risk02026-06-02
3.8.0-rc3.2Low risk02026-06-02
3.8.0-rc3.1Low risk02026-06-02
4.0.0-rc.1Low risk02026-06-02
3.9.0-rc.14Low risk02026-06-01
3.9.0-rc.13Low risk02026-05-30
3.9.0-rc.12Review132026-05-29
3.9.0-rc.11Review132026-05-29
3.9.0-rc.10Review132026-05-29
3.9.0-rc.8Review132026-05-28
3.9.0-rc.9Review132026-05-28
3.9.0-rc.6Review162026-05-28
3.9.0-rc.7Review162026-05-28

Block this in CI

PkgRadar gates @sentio/runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @sentio/[email protected]