PkgRadar

npm · registry.npmjs.org

tolingclaw

Js Split Join Obfuscation: Array-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis.

Why PkgRadar flagged 1.0.8

SeveritySignalEvidence
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/src/ControlUI/dist/assets/index-9xQYH6i8.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.31Low risk02026-06-09
1.0.30Low risk02026-06-09
1.0.29Low risk02026-06-09
1.0.28Low risk02026-06-04
1.0.27Low risk02026-06-04
1.0.26Low risk02026-06-04
1.0.25Low risk02026-06-04
1.0.24Low risk02026-06-04
1.0.22Low risk02026-06-01
1.0.23Low risk02026-06-01
1.0.19Low risk02026-06-01
1.0.20Low risk02026-06-01
1.0.15Low risk02026-06-01
1.0.13Low risk02026-06-01
1.0.12Low risk02026-06-01
1.0.11Low risk02026-06-01
1.0.10Low risk02026-06-01
1.0.8Review402026-05-29
1.0.9Review402026-05-29
1.0.7Review402026-05-28
1.0.4Review402026-05-28
1.0.5Review402026-05-28
1.0.3Review1102026-05-28
1.0.1Review1102026-05-27
1.0.2Review1102026-05-27

Block this in CI

PkgRadar gates tolingclaw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]