PkgRadar

npm · registry.npmjs.org

anentrypoint-design

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 0.0.165

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/dist/247420.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.210Low risk02026-06-12
0.0.209Low risk02026-06-11
0.0.208Low risk02026-06-11
0.0.207Low risk02026-06-11
0.0.206Low risk02026-06-11
0.0.205Low risk02026-06-11
0.0.203Low risk02026-06-11
0.0.204Low risk02026-06-11
0.0.202Low risk02026-06-10
0.0.201Low risk02026-06-10
0.0.200Low risk02026-06-10
0.0.199Low risk02026-06-09
0.0.198Low risk02026-06-07
0.0.197Low risk02026-06-05
0.0.196Low risk02026-06-05
0.0.195Low risk02026-06-05
0.0.194Low risk02026-06-05
0.0.193Low risk02026-06-05
0.0.192Low risk02026-06-04
0.0.190Low risk02026-06-04
0.0.191Low risk02026-06-04
0.0.186Low risk02026-06-04
0.0.185Low risk02026-06-02
0.0.184Low risk02026-06-02
0.0.183Low risk02026-06-02
0.0.182Low risk02026-06-02
0.0.181Low risk02026-06-01
0.0.180Low risk02026-06-01
0.0.179Low risk02026-06-01
0.0.178Low risk02026-05-31
0.0.177Low risk02026-05-31
0.0.176Low risk02026-05-31
0.0.175Low risk02026-05-30
0.0.174Low risk02026-05-30
0.0.173Low risk02026-05-29
0.0.172Low risk02026-05-29
0.0.165Review452026-05-29
0.0.166Review452026-05-29
0.0.163Review312026-05-29
0.0.162Review312026-05-29
0.0.161Review452026-05-29
0.0.160Review312026-05-28
0.0.158Review312026-05-28
0.0.157Review312026-05-28
0.0.146Low risk02026-05-27
0.0.145Low risk02026-05-27
0.0.143Low risk02026-05-26
0.0.144Low risk02026-05-26
0.0.140Low risk02026-05-24
0.0.139Low risk02026-05-24
0.0.138Low risk02026-05-24

Block this in CI

PkgRadar gates anentrypoint-design (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]