PkgRadar

npm · registry.npmjs.org

rebill

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.17.23

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/esm/lottie-E0pOygkZ.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/cjs/lottie-NxKK9TIf.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/components/p-GK75wIKe.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/rebill/p-GK75wIKe.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.17.23Review252026-06-03
1.17.23-beta.1Review252026-06-03
1.17.22Review252026-06-02
1.17.21Review252026-06-02
1.17.20-beta.1Review252026-06-01
1.18.0-beta.2Review252026-06-01
1.18.0-beta.0Review252026-05-29
1.18.0-beta.1Review252026-05-29
1.17.20Review62026-05-28
1.17.19-beta.0Review62026-05-27
1.17.19Review62026-05-27
1.17.18-beta.4Review62026-05-27
1.17.18Review62026-05-27

Block this in CI

PkgRadar gates rebill (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]