PkgRadar

Package evidence

@aot-technologies/[email protected]

Large Javascript Payload, Obfuscation Density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
265
Versions published
7
First published
Sep 2024
Publisher
arun-s-aot

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@aot-technologies/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@aot-technologies/[email protected]"],"fail_on":"review"}'
Publisherarun-s-aot
Artifact bytes12,643,356
Previous version1.0.0
Published2024-10-09T07:41:08.139Z
SHA-2567a921664025686cac71e20a10bf1a2355190a297c70d6ae6357eb98ebe66ecd4

Why flagged

What the scanner saw

Large Javascript Payload

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
1.0.1Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

13 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 13 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowLarge Javascript Payloadmanifest0
lowObfuscation Densitymanifest0

Manifest

Package metadata

Dependencies38
  • @formio/bootstrap32.12.4-rc.1
  • @formio/choices.js10.2.1
  • @formio/semantic2.6.1
  • @formio/text-mask-addons^3.8.0-formio.2
  • @formio/vanilla-text-mask^5.1.1-formio.1
  • abortcontroller-polyfill^1.7.5
  • autocompleter^7.0.1
  • browser-cookies^1.2.0
  • browser-md5-file^1.1.1
  • compare-versions^5.0.1
  • core-js^3.26.1
  • custom-event-polyfill^1.0.7
  • dialog-polyfill^0.5.6
  • dom-autoscroller^2.3.4
  • dompurify^3.0.5
  • downloadjs^1.4.7
  • dragula^3.7.3
  • eventemitter3^4.0.7
  • fast-deep-equal^3.1.3
  • fast-json-patch^3.1.1
  • fetch-ponyfill^7.1.0
  • i18next22.4.12
  • idb^7.1.1
  • inputmask^5.0.9
  • ismobilejs^1.1.1
  • json-logic-js^2.0.2
  • jstimezonedetect^1.0.7
  • jwt-decode^3.1.2
  • lodash^4.17.21
  • moment^2.29.4
  • …and 8 more.