PkgRadar

npm · registry.npmjs.org

socket

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.1.112

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/external/@socketsecurity/registry/external/@npmcli/package-json/index.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/external/@socketsecurity/registry/external/@npmcli/promise-spawn.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/external/@socketsecurity/registry/external/which.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.112Review162026-05-30
1.1.111Review162026-05-29
1.1.110Review212026-05-29
1.1.109Review212026-05-29
1.1.107Review542026-05-28
1.1.108Review542026-05-28
1.1.105Review392026-05-27
1.1.104Review392026-05-27
1.1.102Review392026-05-26
1.1.103Review392026-05-26

Block this in CI

PkgRadar gates socket (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]