PkgRadar

npm · registry.npmjs.org

chrome-devtools-frontend

Known Indicator Filename: package/front_end/third_party/lighthouse/report/bundle.js

Why PkgRadar flagged 1.0.1636056

SeveritySignalEvidence
highKnown Indicator Filenamepackage/front_end/third_party/lighthouse/report/bundle.js · package/front_end/third_party/lighthouse/report/bundle.js
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/front_end/third_party/puppeteer/package/lib/es5-iife/puppeteer-core-browser.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/front_end/third_party/axe-core/axe.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/front_end/third_party/axe-core/axe.min.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/front_end/third_party/json5/lib/index.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/front_end/third_party/codemirror/package/mode/markdown/markdown.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/front_end/third_party/marked/package/lib/marked.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/front_end/third_party/codemirror/package/src/util/misc.js
mediumLarge Javascript Payload6350113 bytes · package/front_end/third_party/lighthouse/lighthouse-dt-bundle.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.1645245Low risk02026-06-13
1.0.1643855Low risk02026-06-11
1.0.1643099Low risk02026-06-10
1.0.1642899Low risk02026-06-09
1.0.1642845Low risk02026-06-08
1.0.1642246Low risk02026-06-07
1.0.1641723Low risk02026-06-06
1.0.1640841Low risk02026-06-05
1.0.1640418Low risk02026-06-04
1.0.1638082Low risk02026-05-30
1.0.1636056Review592026-05-28
1.0.1635876Review362026-05-27
1.0.1632065Review362026-05-26
1.0.1635648Review362026-05-26

Block this in CI

PkgRadar gates chrome-devtools-frontend (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]