deobfuscate-javascript

Fail

Audited by Socket on Jun 26, 2026

3 alerts found:

Securityx2Obfuscated File
SecurityMEDIUM
scripts/unpack.ts
SecurityMEDIUM
fixtures/aaencode.min.js
Obfuscated FileHIGH
fixtures/packed.dean-edwards.min.js

This fragment is an obfuscated eval-based decoder that reconstructs and executes a trivial payload (logging 42). While there is no evidence of overt malicious activity (no exfiltration, persistence, or harmful I/O) in the shown code, the presence of runtime code generation via eval is a meaningful supply-chain red flag because it enables arbitrary behavior if altered elsewhere. Recommended action: review the full package for additional modules/versions and remove or eliminate eval/obfuscation where possible.

Confidence: 90%
Audit Metadata
Analyzed At
Jun 26, 2026, 04:07 PM
Package URL
pkg:socket/skills-sh/JimLiu%2Fdecode-codex%2Fdeobfuscate-javascript%2F@6e18f8d12769c0f2df329967d8384c5e670fde260dfbc4f1e35020c1e17094a9
Security Audit — socket — deobfuscate-javascript