PkgRadar

npm · registry.npmjs.org

yaml-flow

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 8.5.3

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/cli/bundled/card-store-cli.mjs
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/cli/bundled/step-machine-cli.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
8.11.3Low risk02026-06-11
8.11.2Low risk02026-06-11
8.11.1Low risk02026-06-11
8.11.0Low risk02026-06-10
8.9.2Low risk02026-06-10
8.9.1Low risk02026-06-09
8.9.0Low risk02026-06-08
8.8.7Low risk02026-06-05
8.8.6Low risk02026-06-05
8.8.5Low risk02026-06-04
8.8.0Low risk02026-06-04
8.7.1Low risk02026-06-03
8.7.0Low risk02026-06-02
8.6.4Low risk02026-06-01
8.6.3Low risk02026-06-01
8.6.2Low risk02026-05-31
8.6.1Low risk02026-05-31
8.5.3Review502026-05-29
8.5.1Review352026-05-28
8.5.2Review352026-05-28
8.5.0Review352026-05-28
8.4.23Low risk02026-05-26
8.4.25Low risk02026-05-26
8.4.19Low risk02026-05-26
8.4.17Low risk02026-05-25
8.4.18Low risk02026-05-25
8.4.16Low risk02026-05-25
8.4.14Review502026-05-24
8.4.15Review502026-05-24

Block this in CI

PkgRadar gates yaml-flow (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]