PkgRadar

npm · registry.npmjs.org

zhui-plus

Js Decode Then Exec: base64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern.

Why PkgRadar flagged 1.0.10

SeveritySignalEvidence
highJs Decode Then Execbase64 / atob / fromCharCode decode paired with eval / new Function in the same file — canonical obfuscated-loader pattern. · package/packages/components/fileViewer/src/liteofd/font/font_loader.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.95Low risk02026-06-17
1.0.94Low risk02026-06-09
1.0.93Low risk02026-06-09
1.0.92Low risk02026-06-08
1.0.90Low risk02026-06-08
1.0.89Low risk02026-06-08
1.0.88Low risk02026-06-08
1.0.87Low risk02026-06-08
1.0.86Low risk02026-06-08
1.0.84Low risk02026-06-08
1.0.83Low risk02026-06-08
1.0.82Low risk02026-06-08
1.0.81Low risk02026-06-08
1.0.80Low risk02026-06-05
1.0.79Low risk02026-06-05
1.0.78Low risk02026-06-05
1.0.77Low risk02026-06-05
1.0.76Low risk02026-06-04
1.0.75Low risk02026-06-02
1.0.73Low risk02026-06-02
1.0.72Low risk02026-06-02
1.0.71Low risk02026-06-02
1.0.70Low risk02026-06-02
1.0.69Low risk02026-06-02
1.0.67Low risk02026-06-02
1.0.68Low risk02026-06-02
1.0.66Low risk02026-06-02
1.0.65Low risk02026-06-02
1.0.64Low risk02026-06-02
1.0.63Low risk02026-06-02
1.0.62Low risk02026-06-01
1.0.55Low risk02026-06-01
1.0.56Low risk02026-06-01
1.0.50Low risk02026-06-01
1.0.49Low risk02026-06-01
1.0.47Low risk02026-06-01
1.0.46Low risk02026-06-01
1.0.45Low risk02026-06-01
1.0.44Low risk02026-06-01
1.0.43Low risk02026-06-01
1.0.10Review312026-05-29
1.0.0Review402026-05-29
1.0.38Low risk02026-05-29
1.0.37Low risk02026-05-29
1.0.36Low risk02026-05-29
1.0.35Low risk02026-05-29
1.0.34Low risk02026-05-29
1.0.33Low risk02026-05-29
1.0.32Low risk02026-05-29
1.0.31Low risk02026-05-29
1.0.29Review102026-05-28
1.0.30Review102026-05-28
1.0.17Review102026-05-27
1.0.18Review102026-05-27

Block this in CI

PkgRadar gates zhui-plus (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]