npm · registry.npmjs.org
@thomlecter1122/lab-helper-test
Known Indicator Filename: package/router_init.js
Early detection
PkgRadar flagged this 11.3 days before public disclosure
Detected 2026-05-30 · disclosed as MAL-2026-5534 on 2026-06-10
Why PkgRadar flagged 0.0.15
| Severity | Signal | Evidence |
|---|---|---|
| high | Known Indicator Filename | package/router_init.js · package/router_init.js |
| high | Js Decode Then Exec | base64 / atob / fromCharCode decode adjacent to eval / new Function — canonical obfuscated-loader pattern. · package/router_init.js |
| medium | New Account With Lifecycle Hook | package first published 14 day(s) ago, 6 total version(s), has lifecycle hook · package.json |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.0.15 | High risk | 95 | 2026-06-10 |
0.0.16 | High risk | 95 | 2026-06-10 |
0.0.2 | Review | 17 | 2026-05-30 |
0.0.3 | Review | 17 | 2026-05-30 |
Block this in CI
pkgradar gate --ecosystem npm @thomlecter1122/[email protected]