PkgRadar

npm · registry.npmjs.org

@thomlecter1122/lab-helper-test

Known Indicator Filename: package/router_init.js

Early detection

PkgRadar flagged this 11.3 days before public disclosure

Detected 2026-05-30 · disclosed as MAL-2026-5534 on 2026-06-10

Why PkgRadar flagged 0.0.15

SeveritySignalEvidence
highKnown Indicator Filenamepackage/router_init.js · package/router_init.js
highJs Decode Then Execbase64 / atob / fromCharCode decode adjacent to eval / new Function — canonical obfuscated-loader pattern. · package/router_init.js
mediumNew Account With Lifecycle Hookpackage first published 14 day(s) ago, 6 total version(s), has lifecycle hook · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.15High risk952026-06-10
0.0.16High risk952026-06-10
0.0.2Review172026-05-30
0.0.3Review172026-05-30

Block this in CI

PkgRadar gates @thomlecter1122/lab-helper-test (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @thomlecter1122/[email protected]