PkgRadar

Package evidence

@kmkf-fe-packages/[email protected]

Obfuscation Density: high encoded/escaped-token density

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Versions published
1,806Mature · −50% score
First published
Apr 2023
Publisher
raycloud-apaas

Effective trust discount applied: 50% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@kmkf-fe-packages/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@kmkf-fe-packages/[email protected]"],"fail_on":"review"}'
Artifact bytes295,676
Previous version2.7.3-beta.7
Published2026-05-25T07:29:59.805Z
SHA-256b83d265a074838344f9b159b3920d0a6aa04f5c144bb173d7af9699336b25e66

Why flagged

What the scanner saw

Obfuscation Density: high encoded/escaped-token density

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
80Score
2.7.3-beta.8Version
Status history (1 event)
  1. newavailable · risk review · score 80 · status changed

Evidence

Static findings

140 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumObfuscation Densitypackage/dist/esm/components/LogisticsInterception/columnHeader.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/Common/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/PicturePro/PictureName.jsmatched "cUrl "12
Show all 140 findings (low-signal and informational)

Showing 60 of 140 findings.

SeverityKindPathDetailPoints
mediumObfuscation Densitypackage/dist/esm/components/LogisticsInterception/columnHeader.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/Common/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/PicturePro/PictureName.jsmatched "cUrl "12
lowObfuscationpackage/dist/esm/components/Payment/AlipayNick.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/Payment/AlipayNo.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/Payment/AlipayTime.jsmatched "\\u6253"3
lowObfuscationpackage/dist/esm/components/Common/constants/bs_e3.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/Common/constants/bs.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/BS/common/BsType.jsmatched "\\u7C7B"3
lowObfuscationpackage/dist/esm/components/Payment/BuyerNick.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/LogisticsInterception/columnHeader.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/StatusSelect/constants.jsmatched "\\u6210"3
lowObfuscationpackage/dist/esm/components/Common/constants/defaultColumns.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/BS/common/expressCode.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/BS/common/expressCompany.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/commonComponents/GlobalContext/index.jsmatched "\\u6570"3
lowObfuscationpackage/dist/esm/commonComponents/QueryLogisticsTrack/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/commonComponents/ShopList/index.jsmatched "\\u3010"3
lowObfuscationpackage/dist/esm/commonComponents/Wangwang/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/ActualPayment/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/AfterSalesOrderId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/AlipayAccount/index.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/AlipayName/index.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/BS/BsExchange/index.jsmatched "\\u9000"3
lowObfuscationpackage/dist/esm/components/BS/BsLogistics/index.jsmatched "\\uD83D"3
lowObfuscationpackage/dist/esm/components/BS/BsReissue/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BS/BsReturn/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BS/BsSystemOrder/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/BS/DeliveryNo/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/BsE3/BsReissueE3/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BuyerNick/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Cascader/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Checkbox/index.jsmatched "\\u5176"3
lowObfuscationpackage/dist/esm/components/Common/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/CommonInput/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/CommonMultiStatus/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/CommonSystemOrder/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/CommonTradeId/index.jsmatched "\\u65E0"3
lowObfuscationpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "\\u7CFB"3
lowObfuscationpackage/dist/esm/components/ErpTradeId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Express/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/ExpressCode/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/ExpressCompany/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/FlowMarkSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowOverallStatusSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowStatusSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowTag/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowWorkOrderId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowWorkOrderStatus/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/GetFormItem/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/GY/GyReissue/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/GY/GyReturn/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/Input/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/JST/JstItemSelect/index.jsmatched "\\u4F9B"3
lowObfuscationpackage/dist/esm/components/JST/JstSendGood/index.jsmatched "\\u540D"3
lowObfuscationpackage/dist/esm/components/JST/JstSupply/index.jsmatched "\\u4F9B"3
lowObfuscationpackage/dist/esm/components/KM/KmExchange/index.jsmatched "\\u6362"3

Manifest

Package metadata

Scripts4
  • buildyarn run lint && father build
  • linteslint '**/*.{ts,tsx}'
  • lint:fixeslint --fix '**/*.{ts,tsx}'
  • syncyarn build && yalc push
Dependencies5
  • @kmkf-fe-packages/basic-components2.7.3-beta.8
  • @kmkf-fe-packages/kmkf-utils2.7.3-beta.8
  • b64-to-blob^1.2.19
  • html2canvas^1.4.1
  • react-pdf-js^5.1.0