PkgRadar

Package evidence

@kmkf-fe-packages/[email protected]

Obfuscation Density: high encoded/escaped-token density

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@kmkf-fe-packages/[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@kmkf-fe-packages/[email protected]"],"fail_on":"high"}'
Publishershenjianfei
Artifact bytes294,728
Previous version2.7.3-beta.7
Published2026-05-22T08:13:01.598Z
SHA-256d00bcf2becca505b4fb36b112709a3a33f7bbaf9c9081bb8a8410832345482bc

Why flagged

What the scanner saw

Obfuscation Density: high encoded/escaped-token density

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
489Score
2.7.4Version
Status history (1 event)
  1. newavailable · risk high · score 489 · status changed

Related candidates

Linked campaigns and clusters

Publisher / release actor burststale

shenjianfei

4 members · evidence strength 84

Evidence

Static findings

142 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumObfuscation Densitypackage/dist/esm/components/LogisticsInterception/columnHeader.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/Common/index.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/esm/components/Common/index.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/PicturePro/PictureName.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/esm/components/Common/constants/wdt.jshigh encoded/escaped-token density12
Show all 142 findings (low-signal and informational)

Showing 60 of 142 findings.

SeverityKindPathDetailPoints
mediumObfuscation Densitypackage/dist/esm/components/LogisticsInterception/columnHeader.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/Common/index.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/esm/components/Common/index.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "cUrl "12
mediumRemote Payloadpackage/dist/esm/components/PicturePro/PictureName.jsmatched "cUrl "12
mediumObfuscation Densitypackage/dist/esm/components/Common/constants/wdt.jshigh encoded/escaped-token density12
lowObfuscationpackage/dist/esm/components/Payment/AlipayNick.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/Payment/AlipayNo.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/Payment/AlipayTime.jsmatched "\\u6253"3
lowObfuscationpackage/dist/esm/components/Common/constants/bs_e3.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/Common/constants/bs.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/BS/common/BsType.jsmatched "\\u7C7B"3
lowObfuscationpackage/dist/esm/components/Payment/BuyerNick.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/LogisticsInterception/columnHeader.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/LogisticsMoreInterception/columnHeader.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/StatusSelect/constants.jsmatched "\\u6210"3
lowObfuscationpackage/dist/esm/components/Common/constants/defaultColumns.jsmatched "\\u5546"3
lowObfuscationpackage/dist/esm/components/BS/common/expressCode.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/BS/common/expressCompany.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/commonComponents/GlobalContext/index.jsmatched "\\u6570"3
lowObfuscationpackage/dist/esm/commonComponents/QueryLogisticsTrack/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/commonComponents/ShopList/index.jsmatched "\\u3010"3
lowObfuscationpackage/dist/esm/commonComponents/Wangwang/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/ActualPayment/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/AfterSalesOrderId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/AlipayAccount/index.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/AlipayName/index.jsmatched "\\u652F"3
lowObfuscationpackage/dist/esm/components/BS/BsExchange/index.jsmatched "\\u9000"3
lowObfuscationpackage/dist/esm/components/BS/BsLogistics/index.jsmatched "\\uD83D"3
lowObfuscationpackage/dist/esm/components/BS/BsReissue/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BS/BsReturn/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BS/BsSystemOrder/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/BS/DeliveryNo/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/BsE3/BsReissueE3/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/BuyerNick/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Cascader/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Checkbox/index.jsmatched "\\u5176"3
lowObfuscationpackage/dist/esm/components/Common/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/CommonInput/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/CommonMultiStatus/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/CommonSystemOrder/index.jsmatched "\\u81F3"3
lowObfuscationpackage/dist/esm/components/CommonTradeId/index.jsmatched "\\u65E0"3
lowObfuscationpackage/dist/esm/components/ErpTradeId/components/OrderNum/index.jsmatched "\\u7CFB"3
lowObfuscationpackage/dist/esm/components/ErpTradeId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/Express/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/ExpressCode/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/ExpressCompany/index.jsmatched "\\u7269"3
lowObfuscationpackage/dist/esm/components/FlowMarkSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowOverallStatusSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowStatusSelect/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowTag/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowWorkOrderId/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/FlowWorkOrderStatus/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/GetFormItem/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/GY/GyReissue/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/GY/GyReturn/index.jsmatched "\\u5907"3
lowObfuscationpackage/dist/esm/components/Input/index.jsmatched "\\u8BF7"3
lowObfuscationpackage/dist/esm/components/JST/JstItemSelect/index.jsmatched "\\u4F9B"3
lowObfuscationpackage/dist/esm/components/JST/JstSendGood/index.jsmatched "\\u540D"3

Manifest

Package metadata

Scripts4
  • buildyarn run lint && father build
  • linteslint '**/*.{ts,tsx}'
  • lint:fixeslint --fix '**/*.{ts,tsx}'
  • syncyarn build && yalc push
Dependencies5
  • @kmkf-fe-packages/basic-components2.7.4
  • @kmkf-fe-packages/kmkf-utils2.7.4
  • b64-to-blob^1.2.19
  • html2canvas^1.4.1
  • react-pdf-js^5.1.0