PkgRadar

npm · registry.npmjs.org

@xframework-ca-test/cli

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 1.0.28

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/ui/assets/vendor-pdf-DdcBuiYd.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/index.bundle.js
mediumLarge Javascript Payload6704415 bytes · package/dist/ui/assets/index-CUUFwILm.js
mediumLarge Javascript Payload3826169 bytes · package/dist/ui/assets/ReportEditor-CPYJFSx6.js
mediumLarge Javascript Payload3106681 bytes · package/dist/ui/assets/vendor-devex-CkdHfFbX.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.16Low risk02026-06-17
1.0.17Low risk02026-06-17
1.0.35Low risk02026-06-17
1.0.34Low risk02026-06-12
1.0.33Low risk02026-06-10
1.0.32Low risk02026-06-09
1.0.31Low risk02026-06-08
1.0.30Low risk02026-06-02
1.0.28Review872026-05-28
1.0.29Review872026-05-28

Block this in CI

PkgRadar gates @xframework-ca-test/cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @xframework-ca-test/[email protected]