PkgRadar

Package evidence

@cainiaofe/[email protected]

Obfuscation Density: high encoded/escaped-token density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
20
Versions published
4
First published
Nov 2025
Publisher
leannechen

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@cainiaofe/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@cainiaofe/[email protected]"],"fail_on":"review"}'
Publisherleannechen
Artifact bytes14,981,376
Previous version0.0.41-beta.0
Published2025-11-06T11:51:20.769Z
SHA-256aeb76a5962753c3512d600df4e02fcbc4955e0e6c728bd2f518f4d208d187372

Why flagged

What the scanner saw

Obfuscation Density: high encoded/escaped-token density

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
44Score
0.0.41-beta.1Version
Status history (1 event)
  1. newavailable · risk review · score 44 · status changed

Evidence

Static findings

4 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumObfuscation Densitypackage/dist/storybook-docs/159.8467617a.iframe.bundle.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/storybook-docs/5.d13578e461158d9b5dcc.manager.bundle.jshigh encoded/escaped-token density12
mediumLarge Javascript Payloadpackage/dist/storybook-docs/vendors~main.34e429c0e165a71b3b12.manager.bundle.js2071306 bytes10
mediumLarge Javascript Payloadpackage/dist/storybook-docs/vendors~main.ca07da40.iframe.bundle.js12925417 bytes10

Manifest

Package metadata

Scripts8
  • buildcone build
  • build-storybookcone build-storybook
  • commit-msgcommitlint --edit
  • devtnpm run start
  • formatcone format
  • lintcone lint
  • pre-commitlint-staged && node ./version.js
  • startcone start
Dependencies8
  • @antv/g2^5.0.14
  • @cainiaofe/cn-ui^0.9.34
  • @cainiaofe/cn-ui-layout^0.0.13
  • classnames^2.3.2
  • hoist-non-react-statics^3.3.2
  • lodash-es^4.17.21
  • nanoid^4.0.2
  • panda-i18n^0.2.55