PkgRadar

Package evidence

[email protected]

Large Javascript Payload: 2848146 bytes

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
83
Versions published
10
First published
Jan 2026
Publisher
huucuongyd

Recommended action

Review before promoting

Mixed signals: the package has indicators worth reading before allowing the update in automated dependency flows.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"review"}'
Publisherhuucuongyd
Artifact bytes16,411,617
Previous version1.0.7
Published2026-05-25T08:32:58.821Z
SHA-256bad757eebffd257f8bf70eba746a84860908ff38e2d1b4771762b14300d9920f

Why flagged

What the scanner saw

Large Javascript Payload: 2848146 bytes

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

review
Last checked
reviewRisk
76Score
1.0.8Version
Status history (1 event)
  1. newavailable · risk review · score 76 · status changed

Evidence

Static findings

16 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/dist/maplibre-gl-csp-dev.js2848146 bytes10
mediumLarge Javascript Payloadpackage/dist/maplibre-gl-dev.js2992887 bytes10
mediumLarge Javascript Payloadpackage/dist/ndamap-gl-csp-dev.js2809835 bytes10
mediumLarge Javascript Payloadpackage/dist/ndamap-gl-dev.js2950001 bytes10
Show all 16 findings (low-signal and informational)
SeverityKindPathDetailPoints
mediumLarge Javascript Payloadpackage/dist/maplibre-gl-csp-dev.js2848146 bytes10
mediumLarge Javascript Payloadpackage/dist/maplibre-gl-dev.js2992887 bytes10
mediumLarge Javascript Payloadpackage/dist/ndamap-gl-csp-dev.js2809835 bytes10
mediumLarge Javascript Payloadpackage/dist/ndamap-gl-dev.js2950001 bytes10
lowObfuscationpackage/dist/maplibre-gl-csp-worker.jsmatched "\\u02EA"3
lowObfuscationpackage/dist/maplibre-gl-csp.jsmatched "\\u02EA"3
lowObfuscationpackage/dist/maplibre-gl.jsmatched "\\u02EA"3
lowObfuscationpackage/dist/ndamap-gl-csp-worker-dev.jsmatched "\\x00"3
lowObfuscationpackage/dist/ndamap-gl-csp-worker.jsmatched "\\u02EA"3
lowObfuscationpackage/dist/ndamap-gl-csp.jsmatched "\\u02EA"3
lowObfuscationpackage/dist/ndamap-gl.jsmatched "\\u02EA"3
lowObfuscationpackage/src/util/resolve_tokens.test.tsmatched "\\ufff0"3
lowObfuscationpackage/src/symbol/tagged_string.test.tsmatched "\\u200b"3
lowObfuscationpackage/src/symbol/tagged_string.tsmatched "\\u200b"3
lowObfuscationpackage/src/util/unicode_properties.g.tsmatched "\\u02EA"3
lowObfuscationpackage/src/util/util.tsmatched "\\x00"3

Manifest

Package metadata

Scripts42
  • benchmarknode --no-warnings --experimental-transform-types test/bench/run-benchmarks.ts
  • build-benchmarksnpm run build-dev && rollup --configPlugin @rollup/plugin-typescript -c test/bench/rollup_config_benchmarks.ts
  • build-csprollup --configPlugin @rollup/plugin-typescript -c rollup.config.csp.ts --environment BUILD:production
  • build-csp-devrollup --configPlugin @rollup/plugin-typescript -c rollup.config.csp.ts --environment BUILD:dev
  • build-csspostcss -o dist/ndamap-gl.css src/css/maplibre-gl.css
  • build-devrollup --configPlugin @rollup/plugin-typescript -c rollup.config.ts --environment BUILD:dev
  • build-distnpm run build-css && npm run generate-unicode-data && npm run generate-typings && npm run generate-shaders && npm run build-dev && npm run build-csp-dev && npm run build-prod && npm run build-csp
  • build-prodrollup --configPlugin @rollup/plugin-typescript -c rollup.config.ts --environment BUILD:production
  • bundle-statsrollup --configPlugin @rollup/plugin-typescript -c rollup.config.ts --environment BUILD:production,BUNDLE:stats
  • codegenrun-p --print-label generate-dist-package generate-style-code generate-unicode-data generate-struct-arrays generate-shaders && npm run generate-typings
  • docsnpm run generate-docs && docker run --rm -v ${PWD}:/docs squidfunk/mkdocs-material build
  • generate-dist-packagenode --no-warnings build/generate-dist-package.js
  • generate-docstypedoc && node --no-warnings --experimental-transform-types build/generate-docs.ts
  • generate-imagesnode --no-warnings --experimental-transform-types build/generate-doc-images.ts
  • generate-shadersnode --no-warnings --experimental-transform-types build/generate-shaders.ts
  • generate-struct-arraystsx build/generate-struct-arrays.ts
  • generate-style-codenode --no-warnings --experimental-transform-types build/generate-style-code.ts
  • generate-typingsdts-bundle-generator --project tsconfig.codegen.json --export-referenced-types=false --umd-module-name=ndamapgl -o ./dist/ndamap-gl.d.ts ./src/index.ts
  • generate-unicode-datanode --no-warnings --experimental-transform-types build/generate-unicode-data.ts
  • gl-statsnode --no-warnings --experimental-transform-types test/bench/gl-stats.ts
  • linteslint
  • lint-cssstylelint **/*.css --fix -f verbose
  • preparenpm run codegen
  • spellcheckcspell
  • startrun-p watch-css watch-dev start-server
  • start-benchrun-p watch-css watch-benchmarks start-server
  • start-docsdocker run --rm -it -p 8000:8000 -v ${PWD}:/docs squidfunk/mkdocs-material
  • start-serverst --no-cache -H localhost --port 9966 .
  • testrun-p lint lint-css test-render test-unit test-integration test-build
  • test-buildvitest run --config vitest.config.build.ts
  • …and 12 more.
Dependencies22
  • @mapbox/geojson-rewind^0.5.2
  • @mapbox/jsonlint-lines-primitives^2.0.2
  • @mapbox/point-geometry^1.1.0
  • @mapbox/tiny-sdf^2.0.7
  • @mapbox/unitbezier^0.0.1
  • @mapbox/vector-tile^2.0.4
  • @mapbox/whoots-js^3.1.0
  • @maplibre/geojson-vt^5.0.4
  • @maplibre/maplibre-gl-style-spec^24.4.1
  • @maplibre/mlt^1.1.2
  • @maplibre/vt-pbf^4.2.1
  • @types/geojson^7946.0.16
  • @types/supercluster^7.1.3
  • earcut^3.0.2
  • gl-matrix^3.4.4
  • kdbush^4.0.2
  • murmurhash-js^1.0.0
  • pbf^4.0.1
  • potpack^2.1.0
  • quickselect^3.0.0
  • supercluster^8.0.1
  • tinyqueue^3.0.0