PkgRadar

npm · registry.npmjs.org

comp-hub

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 0.28.7

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/website/main/assets/vendor-ui-CGT0cG1n.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.30.1Low risk02026-06-17
0.30.0Low risk02026-06-17
0.29.9Low risk02026-06-12
0.29.8Low risk02026-06-03
0.29.7Low risk02026-06-02
0.28.7Review282026-05-31
0.28.6Review282026-05-30
0.28.5Review282026-05-29
0.28.4Review572026-05-28
0.28.3Review292026-05-26
0.28.2Review302026-05-25
0.27.20Review302026-05-24
0.28.1Review302026-05-24

Block this in CI

PkgRadar gates comp-hub (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]