npm · registry.npmjs.org
tocco-devcon
Remote Payload: matched "Invoke-WebRequest"
Why PkgRadar flagged 3.16.14
| Severity | Signal | Evidence |
|---|---|---|
| medium | Remote Payload | matched "Invoke-WebRequest" · package/dist/chunk-2456.29756bfca4b18c959ca6.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/chunk-2981.98c2ee360caaa7c33765.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/chunk-6335.470d01b24ae4bf68035b.js |
| medium | Remote Payload | matched "cURL " · package/dist/chunk-7802.518ecb2a2b0c0a4f2d75.js |
| medium | Remote Payload | matched "cURL " · package/dist/chunk-8077.1ddd76f2c7f821c3e4e1.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/ckeditor4/plugins/codemirror/js/beautify.min.js |
| medium | Obfuscation Density | high encoded/escaped-token density · package/dist/ckeditor4/plugins/codemirror/js/codemirror.min.js |
| medium | Remote Payload | matched "iwr " · package/dist/ckeditor4/plugins/placeholder/lang/cy.js |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
3.16.15 | Low risk | 0 | 2026-06-03 |
3.15.1-playground | Low risk | 0 | 2026-06-03 |
3.16.14 | Review | 48 | 2026-05-25 |
3.15.0-playground | Review | 48 | 2026-05-25 |
3.15.62 | Review | 48 | 2026-05-25 |
Block this in CI
pkgradar gate --ecosystem npm [email protected]