PkgRadar

Package evidence

[email protected]

Js Remote Exe Exec, Js Split Join Obfuscation, New Account With Lifecycle Hook +8 more

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
3
First published
Aug 2026
Publisher
dikacode

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publisherdikacode
Artifact bytes43,358,318
Previous version3.8.51
Published2026-08-08T12:24:09.762Z
SHA-256ea082d9f36e39fa3aa86d6fa4c0726a3db77974b2599244d0825cb2a5e77bfa1

Why flagged

What the scanner saw

Js Remote Exe Exec

1 candidate cluster(s) currently reference this release.

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
223Score
3.8.52Version
Status history (1 event)
  1. newavailable · risk high · score 223 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burstactive

Publisher burst: dikacode

3 members · evidence strength 77
Publisher / release actor burstcandidate

Publisher burst: dikacode

3 members · max score 223

Evidence

Static findings

51 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highJs Remote Exe Execmanifest45
highJs Remote Exe Execmanifest45
highJs Split Join Obfuscationmanifest40
highNew Account With Lifecycle Hookmanifest25
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumCredential file accessmanifest10
mediumSuspicious Publish Contextmanifest10
Show all 51 findings (low-signal and informational)
SeverityKindPathDetailPoints
highJs Remote Exe Execmanifest45
highJs Remote Exe Execmanifest45
highJs Split Join Obfuscationmanifest40
highNew Account With Lifecycle Hookmanifest25
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumTls Verification Disabledmanifest12
mediumTls Verification Disabledmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumRemote Payloadmanifest12
mediumCredential file accessmanifest10
mediumSuspicious Publish Contextmanifest10
lowMessenger Bot Endpointmanifest5
lowCredential file accessmanifest5
lowMessenger Bot Endpointmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowCredential file accessmanifest5
lowMessenger Bot Endpointmanifest5
lowInstall-time lifecycle scriptmanifest5
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0
lowObfuscation Densitymanifest0

Manifest

Package metadata

Dependencies74
  • @aws-sdk/client-bedrock-runtime^3.1073.0
  • @dnd-kit/core^6.3.1
  • @dnd-kit/sortable^10.0.0
  • @dnd-kit/utilities^3.2.2
  • @lobehub/icons^5.8.0
  • @modelcontextprotocol/sdk^1.29.0
  • @monaco-editor/react^4.7.0
  • @ngrok/ngrok^1.7.0
  • @swc/helpers0.5.23
  • @toon-format/toon^4.1.0
  • @types/mdx^2.0.13
  • @xyflow/react^12.11.1
  • axios^1.16.1
  • bcryptjs^3.0.3
  • bottleneck^2.19.5
  • clsx^2.1.1
  • commander^15.0.0
  • csv-stringify^6.7.0
  • dompurify^3.4.12
  • express^5.2.1
  • fetch-socks^1.3.3
  • fflate^0.8.3
  • fumadocs-core^16.10.5
  • fumadocs-ui^16.10.5
  • http-proxy-middleware^4.0.0
  • https-proxy-agent^9.0.0
  • ink^7.0.3
  • ink-spinner^5.0.0
  • ink-text-input^6.0.0
  • ioredis^5.10.1
  • …and 44 more.
Optional dependencies8
  • @atjsh/llmlingua-22.0.3
  • @huggingface/transformers3.5.2
  • @tensorflow/tfjs4.22.0
  • better-sqlite3^13.0.2
  • js-tiktoken^1.0.20
  • keytar^7.9.0
  • tls-client-node^0.2.0
  • wreq-js^2.3.1