PkgRadar

npm · registry.npmjs.org

@things-factory/operato-gangsters

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 6.1.78

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/activate.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/checkin.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/signin.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist-client/auth/signup.js
mediumRemote Payloadmatched "curl " · package/installer/install.sh
mediumRemote Payloadmatched "curl " · package/installer/upgrade.sh

Scanned versions

VersionVerdictScoreScanned (UTC)
6.1.78Review372026-06-11
6.1.73Review372026-06-11
6.1.81Review372026-06-11
9.2.27Low risk02026-06-11
9.2.26Low risk02026-06-09
9.2.25Low risk02026-06-08
10.0.0-beta.99Low risk02026-06-07
10.0.0-beta.97Low risk02026-06-03
10.0.0-beta.96Low risk02026-05-31
10.0.0-beta.95Low risk02026-05-30
10.0.0-beta.94Low risk02026-05-28
10.0.0-beta.93Low risk02026-05-26
10.0.0-beta.92Low risk02026-05-26
10.0.0-beta.91Low risk02026-05-26
10.0.0-beta.90Low risk02026-05-24
10.0.0-beta.89Low risk02026-05-24

Block this in CI

PkgRadar gates @things-factory/operato-gangsters (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @things-factory/[email protected]