PkgRadar

npm · registry.npmjs.org

bitmovin-player

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 8.261.0-beta.0

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/modules/bitmovinplayer-core.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/modules/bitmovinplayer-core.prod.js
mediumLarge Javascript Payload2341899 bytes · package/bitmovinplayer.js
mediumLarge Javascript Payload2250984 bytes · package/bitmovinplayer.prod.js

Scanned versions

VersionVerdictScoreScanned (UTC)
8.263.0Low risk02026-06-16
8.263.0-rc.0Low risk02026-06-16
8.138.0-alpha.9Low risk02026-06-15
8.263.0-alpha.0Low risk02026-06-15
8.261.1-alpha.7Low risk02026-06-08
8.261.1-alpha.6Low risk02026-06-08
8.261.1-alpha.5Low risk02026-06-08
8.261.1-alpha.4Low risk02026-06-08
8.262.0Low risk02026-06-08
8.261.1-alpha.3Low risk02026-06-08
8.262.0-rc.0Low risk02026-06-08
8.261.1-alpha.2Low risk02026-06-08
8.261.1-alpha.1Low risk02026-06-08
8.261.1-alpha.0Low risk02026-06-02
8.262.0-beta.0Low risk02026-06-01
8.261.0Low risk02026-06-01
8.261.0-rc.0Low risk02026-06-01
8.261.0-beta.0Review212026-05-28
8.260.0-rc.0Review62026-05-26
8.260.0Review62026-05-26

Block this in CI

PkgRadar gates bitmovin-player (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]