← Home

@0gfoundation/0g-compute-ts-sdk

5
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

overi0g-jiahao0g-will0g-xieymh3570g-peterzhang

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:web-ui/out/_next/static/chunks/4926-deb1356d46a05531.js AI (source-diff): Webpack bundle output from documented web-ui build, no malicious behavior in sample. ai
source-diff net-exec-file:web-ui/out/_next/static/chunks/4926-deb1356d46a05531.js AI (source-diff): Bundled crypto/network libs (ethers etc.) in webpack chunk, not a dropper. ai
source-diff obfuscated-file:web-ui/out/_next/static/chunks/1178-d6c88024cfcdc774.js AI (source-diff): Webpack-bundled Next.js static chunk; sample shows ethers/crypto lib code, not obfuscation. ai
source-diff net-exec-file:web-ui/out/_next/static/chunks/1178-d6c88024cfcdc774.js AI (source-diff): Bundled web-ui asset; network+exec pattern is normal bundler polyfill code. ai
npm-metadata bundled-binaries AI (npm-metadata): dcap-qvl wasm is a documented TEE attestation component for 0G Compute. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in bundled Next.js chunk is standard webpack/framework output, not intentional obfuscation. ai
phantom-deps phantom-dep:util AI (phantom-deps): Browser polyfill declared for bundler config; not a direct import but legitimately needed. ai
phantom-deps phantom-dep:brotli AI (phantom-deps): Declared as runtime dep for compression; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:buffer AI (phantom-deps): Browser polyfill in bundler config; stable false positive for this package. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Used in CLI runtime config loading; phantom-dep heuristic false positive. ai
semgrep semgrep:env-spread AI (semgrep): Fires in test file saving/restoring process.env — standard test setup pattern, not malicious. ai
phantom-deps phantom-dep:circomlibjs AI (phantom-deps): ZK library dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:stream-browserify AI (phantom-deps): Browser polyfill in bundler config; stable false positive. ai
phantom-deps phantom-dep:@ethersproject/bytes AI (phantom-deps): Ethers utility dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@ethersproject/keccak256 AI (phantom-deps): Ethers utility dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:crypto-js AI (phantom-deps): Declared dep used transitively; stable false positive for this package. ai
semgrep semgrep:child-process-import AI (semgrep): Used in integration test harness to invoke the CLI binary under test. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is part of standard ethers keccak256 signing flow, not payload hiding. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding a base64 config response field — normal API response handling. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Fires in bundled Next.js web-UI static output; raw IPs in minified bundles are common for default/example configs. ai

Versions (showing 5 of 5)

Version Deps Published
0.9.0 21 / 33
0.8.4 21 / 33
0.8.3 21 / 33
0.8.2 21 / 33
0.8.0 21 / 33

v0.9.0

24 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • binary/dcap-qvl-web_bg.wasm

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1080.77f62d93678a6e7f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1178-d6c88024cfcdc774.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: web-ui/out/_next/static/chunks/1178-d6c88024cfcdc774.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1441.7782799f0594d94a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: web-ui/out/_next/static/chunks/1441.7782799f0594d94a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1600-fe6c01f52f7ba0b1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1847-9dde50f29713b3ce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/1937.5ccc2897f24382c1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2159.44d9d125d6ae71b2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2229.80e38290e9fdce3e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2243-d05ef5361376e236.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/230.c45b0f383a36baf2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2330.418722c0fa910267.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2570.1c7e887e49ade557.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2707.5c8c2f27195ee293.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/2a532c78-f623f4c86d3b3cff.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/3209.4b5cebf3b769fda3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/3229.debe603959f6dc24.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/3252.498db7ea32960bee.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/3399.27686954e9d4497d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/3478.4f8ede042918194d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/363.430f2b010773b94b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.4

18 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • binary/dcap-qvl-web_bg.wasm

HIGH New obfuscated file: web-ui/out/_next/static/chunks/4926-deb1356d46a05531.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: web-ui/out/_next/static/chunks/4926-deb1356d46a05531.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/7f1e23b2-57943e63f31b21f6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/8348-5e25c9ba5a413101.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/8983-6ae59455f014f7f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: lib.esm/index-e381c802.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/layout-dc25d2ace5d2e796.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/inference/chat/page-0aef590402bc4add.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/inference/image-gen/page-357c495838581643.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/inference/image-edit/page-460f1e12f533f2ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/inference/speech-to-text/page-5d54f0d211fe54c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/x402-demo/page-605a20b2369a90f7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/page-6c5017f231dea9ca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/wallet/page-6d63327059275d7c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/app/inference/page-d7c0bc3df3f6b34a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: web-ui/out/_next/static/chunks/webpack-cb6b9113c0b96998.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.