PkgRadar

npm · registry.npmjs.org

damn-vulnerable-ai-agent

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 0.9.0

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/scenarios/encoding-bypass-base64/vulnerable/handler.js
mediumRemote Payloadmatched "curl " · package/test-playground-api.sh
mediumRemote Payloadmatched "curl " · package/scenarios/timing-side-channel-inference/vulnerable/timing-attack.sh
mediumCredential file accessmatched ".aws/" · package/scenarios/behavioral-drift-to-exfil/vulnerable/index.js
mediumCredential file accessmatched "id_rsa" · package/scenarios/supply-chain-to-rce/vulnerable/skills/metrics-heartbeat.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.9.0Review312026-05-28
0.9.1Review312026-05-28

Block this in CI

PkgRadar gates damn-vulnerable-ai-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]