PkgRadar

Package evidence

@desirecore/[email protected]

Reverse Shell, Obfuscation Density, Large Javascript Payload

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
60
Versions published
17
First published
Mar 2026
Publisher
yige

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@desirecore/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@desirecore/[email protected]"],"fail_on":"high"}'
Publisheryige
Artifact bytes15,827,760
Previous version0.2.10
Published2026-03-26T06:13:50.469Z
SHA-256aeca67ac340d8dc045fa5ab44f46d00d8d6ded2bc1e55f8c8e593a212622b98e

Why flagged

What the scanner saw

Reverse Shell

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
50Score
0.2.11Version
Status history (1 event)
  1. newavailable · risk high · score 50 · status changed

Evidence

Static findings

13 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
highReverse Shellpackage/dist/super-doc.engine.core.esm.js40
highReverse Shellpackage/dist/super-doc.engine.core.js40
highReverse Shellpackage/dist/super-doc.engine.esm.js40
highReverse Shellpackage/dist/super-doc.engine.js40
highReverse Shellpackage/dist/super-doc.stream.esm.js40
highReverse Shellpackage/dist/super-doc.stream.js40
Show all 13 findings (low-signal and informational)
SeverityKindPathDetailPoints
highReverse Shellpackage/dist/super-doc.engine.core.esm.js40
highReverse Shellpackage/dist/super-doc.engine.core.js40
highReverse Shellpackage/dist/super-doc.engine.esm.js40
highReverse Shellpackage/dist/super-doc.engine.js40
highReverse Shellpackage/dist/super-doc.stream.esm.js40
highReverse Shellpackage/dist/super-doc.stream.js40
lowObfuscation Densitypackage/dist/addons/advance/cherry-codeblock-echarts-plugin.esm.js0
lowObfuscation Densitypackage/dist/addons/advance/cherry-codeblock-echarts-plugin.js0
lowLarge Javascript Payloadpackage/dist/super-doc.core.js0
lowLarge Javascript Payloadpackage/dist/super-doc.esm.js0
lowLarge Javascript Payloadpackage/dist/super-doc.js0
lowLarge Javascript Payloadpackage/dist/super-doc.wysiwyg.esm.js0
lowLarge Javascript Payloadpackage/dist/super-doc.wysiwyg.js0

Manifest

Package metadata

Scripts 20

Sign in to view install / lifecycle script contents.

Dependencies8
  • @milkdown/crepe^7.19.0
  • @milkdown/kit^7.19.0
  • @types/codemirror^0.0.108
  • crypto-js^4.2.0
  • dompurify^3.2.6
  • htmlparser2^10.0.0
  • jsdom~19.0.0
  • ws^8.18.0
Optional dependencies1
  • mermaid9.4.3