PkgRadar

Package evidence

[email protected]

Remote Payload: matched "Invoke-WebRequest"

Recommended action

Block this update

Static evidence trips multiple high-signal indicators. Quarantine the release until the publisher validates the change or you can rule out the indicators below.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["[email protected]"],"fail_on":"high"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["[email protected]"],"fail_on":"high"}'
Publishertocconpm
Artifact bytes4,644,571
Previous version3.16.13
Published2026-05-25T02:53:07.866Z
SHA-2563f59382d53a1dad23d81caa82c13a9ab21bd51f72aa59bfdb7a9f2c2da61b9c8

Why flagged

What the scanner saw

Remote Payload: matched "Invoke-WebRequest"

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

high
Last checked
highRisk
372Score
3.16.14Version
Status history (1 event)
  1. newavailable · risk high · score 372 · status changed

Evidence

Static findings

100 static · 0 from release diff · showing high-signal first.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/dist/chunk-2456.29756bfca4b18c959ca6.jsmatched "Invoke-WebRequest"12
mediumObfuscation Densitypackage/dist/chunk-2981.98c2ee360caaa7c33765.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-6335.470d01b24ae4bf68035b.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/chunk-7802.518ecb2a2b0c0a4f2d75.jsmatched "cURL "12
mediumRemote Payloadpackage/dist/chunk-8077.1ddd76f2c7f821c3e4e1.jsmatched "cURL "12
mediumObfuscation Densitypackage/dist/ckeditor4/plugins/codemirror/js/beautify.min.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/ckeditor4/plugins/codemirror/js/codemirror.min.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/ckeditor4/plugins/placeholder/lang/cy.jsmatched "iwr "12
Show all 100 findings (low-signal and informational)

Showing 60 of 100 findings.

SeverityKindPathDetailPoints
mediumRemote Payloadpackage/dist/chunk-2456.29756bfca4b18c959ca6.jsmatched "Invoke-WebRequest"12
mediumObfuscation Densitypackage/dist/chunk-2981.98c2ee360caaa7c33765.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/chunk-6335.470d01b24ae4bf68035b.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/chunk-7802.518ecb2a2b0c0a4f2d75.jsmatched "cURL "12
mediumRemote Payloadpackage/dist/chunk-8077.1ddd76f2c7f821c3e4e1.jsmatched "cURL "12
mediumObfuscation Densitypackage/dist/ckeditor4/plugins/codemirror/js/beautify.min.jshigh encoded/escaped-token density12
mediumObfuscation Densitypackage/dist/ckeditor4/plugins/codemirror/js/codemirror.min.jshigh encoded/escaped-token density12
mediumRemote Payloadpackage/dist/ckeditor4/plugins/placeholder/lang/cy.jsmatched "iwr "12
lowObfuscationpackage/dist/chunk-1057.c291f0104af5ce85a083.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-1170.01085552cbe0f87eaff3.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-1211.5bc45aa5ab8617293d62.jsmatched "\\u2053"3
lowObfuscationpackage/dist/chunk-1239.9a161e6a1e146d2ab202.jsmatched "\\x7f"3
lowObfuscationpackage/dist/chunk-1255.7c08b883fb543a25bb00.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-1281.6f8230ee148d22acd9ba.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-1742.b594006e421e8ed9b2d7.jsmatched "\\u00a0"3
lowObfuscationpackage/dist/chunk-1843.02797db5e75e83fd36e8.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-2030.4951dcd227d3704a4fcc.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-2451.61a6b346a79369985f59.jsmatched "\\u00A2"3
lowObfuscationpackage/dist/chunk-2575.1636f1388039b52492ef.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-2682.053b8bf88db3ed64b4e6.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-2797.0e68a5098b4cedc22010.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-2887.14fdf774879806120ce1.jsmatched "\\ud800"3
lowObfuscationpackage/dist/chunk-2981.98c2ee360caaa7c33765.jsmatched "\\xAA"3
lowObfuscationpackage/dist/chunk-3124.bea696995a228c31db0b.jsmatched "\\xAA"3
lowObfuscationpackage/dist/chunk-3136.24899c8e6aa4bbc9d161.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-3204.3485aea122d318f3bf45.jsmatched "\\xff"3
lowObfuscationpackage/dist/chunk-3330.dba7fcfa2f18dc40b83a.jsmatched "\\u0080"3
lowObfuscationpackage/dist/chunk-3489.466edac576604c59e848.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-3537.8f26ceec3e5f5c219598.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-3780.42ce8a35ca66ad4964b4.jsmatched "\\u00a1"3
lowObfuscationpackage/dist/chunk-3951.133acada0530da82b548.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-4108.23962eaf66f84fc45be7.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-4194.ed870f1ddb07bdbec96f.jsmatched "\\u00BF"3
lowObfuscationpackage/dist/chunk-4413.2359b180122808da21f3.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-4417.631fd41a513585c58eb8.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-4570.79edb57d646f666055be.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-4678.2cb01622019e29dc1b5a.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-47.aff8057656217a04a1dd.jsmatched "\\u00A2"3
lowObfuscationpackage/dist/chunk-470.95373281fe1fd48e5afe.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-5009.d21fea80c9efed8d075e.jsmatched "\\x00"3
lowObfuscationpackage/dist/chunk-5010.3cc61dbd2547a493fcce.jsmatched "\\x3c"3
lowObfuscationpackage/dist/chunk-5029.513d1d2c683435dd2c06.jsmatched "\\x3c"3
lowObfuscationpackage/dist/chunk-5243.6ec0dc450e0f083db6eb.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-5408.3fa30543329798f9a375.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-5631.a496cc454b140386f0eb.jsmatched "\\u00A0"3
lowObfuscationpackage/dist/chunk-5802.6cb009df0edde3d619da.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-6147.81c90d98ef1e2eccdfac.jsmatched "\\xa1"3
lowObfuscationpackage/dist/chunk-616.2bc2e8ef3a4b1598a55f.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-6335.470d01b24ae4bf68035b.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-638.e45ed40ddbc8a39e31ee.jsmatched "\\x61"3
lowObfuscationpackage/dist/chunk-6396.1236f855af4e34079dd2.jsmatched "\\x7f"3
lowObfuscationpackage/dist/chunk-6623.a1e93bb42672ab731d2a.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-6667.999060d7b12c6edc0074.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-6679.042d5a0609d68e0ccae8.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-6809.4db7d0f6a14a65ff799a.jsmatched "\\u2192"3
lowObfuscationpackage/dist/chunk-7145.d57e54da6f1280274316.jsmatched "\\u00BF"3
lowObfuscationpackage/dist/chunk-7210.b4e2a31d61212bf36fe1.jsmatched "fromCharCode"3
lowObfuscationpackage/dist/chunk-7217.f52b9da34e5bfa680101.jsmatched "\\xC0"3
lowObfuscationpackage/dist/chunk-7385.a9cf1a2e9e01c7d77870.jsmatched "\\x3e"3
lowObfuscationpackage/dist/chunk-7627.518b0d5272327890bacf.jsmatched "\\x3e"3

Manifest

Package metadata

Scripts2
  • compile:prodcd ../../../ && yarn run compile:prod --package=devcon
  • prepackyarn run compile:prod