Recommended action
Block this updateStatic evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.
Block this release in CIcurl · GitHub Actions
Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer $PKGRADAR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'GitHub Actions step:
- name: PkgRadar gate
run: |
curl -fsS https://pkgradar.com/gate/npm \
-H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"specs":["[email protected]"],"fail_on":"high"}'Why flagged
What the scanner saw
Remote Payload: matched "wget "
Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.
Availability ledger
available
Status history (1 event)
- new → available · risk high · score 110 · status changed
Related candidates
Linked campaigns and clusters
stevenvelozo
6 members · evidence strength 84Evidence
Static findings
14 static · 0 from release diff · showing high-signal first.
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/html/codejar-bundle.js | matched "wget " | 12 |
| medium | Obfuscation Density | package/html/codejar-bundle.js | high encoded/escaped-token density | 12 |
| medium | Remote Payload | package/web-application/codejar-bundle.js | matched "wget " | 12 |
| medium | Obfuscation Density | package/web-application/codejar-bundle.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/html/codemirror-bundle.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/web-application/codemirror-bundle.js | high encoded/escaped-token density | 12 |
| medium | Large Javascript Payload | package/web-application/retold-content-system.compatible.js | 3092366 bytes | 10 |
| medium | Large Javascript Payload | package/web-application/retold-content-system.js | 2932037 bytes | 10 |
Show all 14 findings (low-signal and informational)
| Severity | Kind | Path | Detail | Points |
|---|---|---|---|---|
| medium | Remote Payload | package/html/codejar-bundle.js | matched "wget " | 12 |
| medium | Obfuscation Density | package/html/codejar-bundle.js | high encoded/escaped-token density | 12 |
| medium | Remote Payload | package/web-application/codejar-bundle.js | matched "wget " | 12 |
| medium | Obfuscation Density | package/web-application/codejar-bundle.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/html/codemirror-bundle.js | high encoded/escaped-token density | 12 |
| medium | Obfuscation Density | package/web-application/codemirror-bundle.js | high encoded/escaped-token density | 12 |
| medium | Large Javascript Payload | package/web-application/retold-content-system.compatible.js | 3092366 bytes | 10 |
| medium | Large Javascript Payload | package/web-application/retold-content-system.js | 2932037 bytes | 10 |
| low | Obfuscation | package/html/codejar-bundle.js | matched "\\u0410" | 3 |
| low | Obfuscation | package/web-application/codejar-bundle.js | matched "\\u0410" | 3 |
| low | Obfuscation | package/html/codemirror-bundle.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/web-application/codemirror-bundle.js | matched "fromCharCode" | 3 |
| low | Obfuscation | package/source/Pict-Application-ContentEditor.js | matched "\\u00B7" | 3 |
| low | Obfuscation | package/web-application/js/pict.min.js | matched "fromCharCode" | 3 |
Manifest
Package metadata
Scripts19
brandnode node_modules/pict-section-theme/bin/pict-section-theme-brand.js --manifest ../../../Retold-Modules-Manifest.json --module retold-content-system --favicons web-application/faviconsbuildnpx quack build && npx quack copybuild-allnpm run build-codemirror && npm run build-codejar && npm run buildbuild-codejarnode build/build-codejar-bundle.jsbuild-codemirrornode build/build-codemirror-bundle.jspostpublishnpx quack release postpublishpostversionnpx quack release postversionprebuildnpm run brandprepacknpm run build-allprepublishOnlynpm testpublish:dockernpx quack release publish --imagerelease:majornpx quack release majorrelease:major:imagenpx quack release major --imagerelease:minornpx quack release minorrelease:minor:imagenpx quack release minor --imagerelease:patchnpx quack release patchrelease:patch:imagenpx quack release patch --imagestartnode source/cli/ContentSystem-CLI-Run.js servetestecho "Error: no test specified" && exit 0
Dependencies19
fable^3.1.75orator^6.1.2orator-serviceserver-restify^2.0.11pict^1.0.370pict-application^1.0.34pict-provider^1.0.13pict-provider-theme^1.0.1pict-provider-vocabulary^1.0.1pict-section-code^1.0.11pict-section-content^1.0.3pict-section-filebrowser^1.0.4pict-section-inlinedocumentation^1.0.1pict-section-login^1.0.0pict-section-markdowneditor^1.0.15pict-section-modal^1.1.1pict-section-theme^1.0.5pict-service-commandlineutility^1.0.19pict-view^1.0.68ultravisor-beacon^1.0.1