PkgRadar

npm · registry.npmjs.org

base62-86x

no static findings

Early detection

PkgRadar flagged this 1h before public disclosure

Detected 2026-06-25 · disclosed as MAL-2026-6446 on 2026-06-25

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.4High risk02026-06-25
5.0.5Review102026-06-25

Block this in CI

PkgRadar gates base62-86x (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]