PkgRadar

npm · registry.npmjs.org

@zeniai/web-app-ui

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 5.1.64-dev

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/assets/pdf-CojJ326Z.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/assets/lottie-Byecfo2L.js

Scanned versions

VersionVerdictScoreScanned (UTC)
5.1.82-betaDI1Low risk02026-06-13
5.1.84-prodLow risk02026-06-12
5.1.84-nextLow risk02026-06-12
5.1.84-qaLow risk02026-06-12
5.1.84-devLow risk02026-06-12
5.1.83-prodLow risk02026-06-10
5.1.83-nextLow risk02026-06-10
5.1.83-qaLow risk02026-06-10
5.1.83-devLow risk02026-06-10
5.1.82-qaLow risk02026-06-10
4.13.29-devLow risk02026-06-10
5.0.64-nextLow risk02026-06-10
5.1.82-devLow risk02026-06-10
4.14.24-delhi-betaRR0Low risk02026-06-10
4.14.24-delhi-betaAK2Low risk02026-06-10
5.1.81-prodLow risk02026-06-09
5.1.81-nextLow risk02026-06-09
5.1.81-devLow risk02026-06-09
5.1.80-devLow risk02026-06-09
5.1.80-qaLow risk02026-06-09
5.1.79-qaLow risk02026-06-09
5.1.79-devLow risk02026-06-09
5.1.78-qaLow risk02026-06-08
5.1.78-devLow risk02026-06-08
5.1.77-qaLow risk02026-06-08
5.1.77-devLow risk02026-06-08
5.1.76-prodLow risk02026-06-08
5.1.76-nextLow risk02026-06-08
5.1.76-qaLow risk02026-06-08
5.1.76-devLow risk02026-06-08
5.1.75-devLow risk02026-06-08
5.1.75-qaLow risk02026-06-08
5.1.74-devLow risk02026-06-06
5.1.73-prodLow risk02026-06-05
5.1.73-devLow risk02026-06-05
5.1.73-qaLow risk02026-06-05
5.1.72-prodLow risk02026-06-05
5.1.72-qaLow risk02026-06-05
5.1.71-devLow risk02026-06-05
5.1.70-devLow risk02026-06-05
5.1.69-devLow risk02026-06-03
5.1.69-qaLow risk02026-06-03
5.1.68-prodLow risk02026-06-03
5.1.68-nextLow risk02026-06-03
5.1.68-qaLow risk02026-06-03
5.1.68-devLow risk02026-06-03
5.1.67-prodLow risk02026-06-01
5.1.67-nextLow risk02026-06-01
5.1.67-qaLow risk02026-06-01
5.1.67-devLow risk02026-06-01
5.1.66-devLow risk02026-05-30
5.1.66-qaLow risk02026-05-30
5.1.65-nextLow risk02026-05-29
5.1.65-prodLow risk02026-05-29
5.1.64-devReview252026-05-29
5.1.64-qaReview252026-05-29
5.1.62-devReview252026-05-29
5.1.62-qaReview252026-05-29
5.1.61-devReview252026-05-28
5.1.61-qaReview252026-05-28
5.1.55-pune-betaAS1Review62026-05-27
5.1.40-sunnyvale-betaNB1Review62026-05-27
5.1.44-qaReview62026-05-26
5.1.45-devReview62026-05-26
5.1.43-nextReview62026-05-26
5.1.43-prodReview62026-05-26
5.1.37-qaReview102026-05-26
5.1.37-devReview102026-05-26
5.1.36-dev-betaAR1Review102026-05-25
5.1.36-mohali-betaAR1Review202026-05-25
5.1.36-qaReview202026-05-25
5.1.35-dev-betaAN3Review202026-05-25
5.1.36-devReview202026-05-25

Block this in CI

PkgRadar gates @zeniai/web-app-ui (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @zeniai/[email protected]