PkgRadar

npm · registry.npmjs.org

environment-gate

Js Decode Then Exec: base64 / atob / fromCharCode decode adjacent to eval / new Function — canonical obfuscated-loader pattern.

Why PkgRadar flagged 7.3.6

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode adjacent to eval / new Function — canonical obfuscated-loader pattern. · package/index.js
mediumSuspicious Publish Context{"package_age_days":0,"publisher":"jeandupont24","burst_same_day":2,"burst_week":2,"lure":{"kind":"token_affix","target":"environment"},"version_anomaly":true,"new_account":true}

Scanned versions

VersionVerdictScoreScanned (UTC)
7.3.6Review552026-06-13
7.3.5Review552026-06-13

Block this in CI

PkgRadar gates environment-gate (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]