@bitgo-beta/sdk-coin-avaxp
BitGo's SDK coin library for avaxp coin
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation; legitimate CI/CD transition for BitGo org. | ai | |
| source-diff | obfuscated-file:dist/src/lib/atomicInCTransactionBuilder.js | AI (source-diff): TypeScript compiler output with long lines from hex test data; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/src/lib/deprecatedTransaction.js | AI (source-diff): Standard tsc CommonJS output; long lines are blockchain hex fixtures. | ai | |
| source-diff | obfuscated-file:dist/src/lib/deprecatedTransactionBuilder.js | AI (source-diff): Standard tsc CommonJS output; long lines are blockchain hex fixtures. | ai | |
| source-diff | obfuscated-file:dist/test/resources/tx/exportC.js | AI (source-diff): Test resource file with hex-encoded AVAX transaction data; expected for this package. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/exportC2PTxBuilder.js | AI (source-diff): Standard tsc test output with CommonJS boilerplate; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/src/lib/exportInCTxBuilder.js | AI (source-diff): Standard tsc CommonJS output; long lines are blockchain hex fixtures. | ai | |
| source-diff | obfuscated-file:dist/src/lib/permissionlessValidatorTxBuilder.js | AI (source-diff): Standard tsc CommonJS output; long lines are blockchain hex fixtures. | ai | |
| source-diff | obfuscated-file:dist/test/unit/lib/permissionlessValidatorTxBuilder.js | AI (source-diff): Standard tsc test output with CommonJS boilerplate; not obfuscated. | ai | |
| source-diff | encoded-string-file:dist/test/resources/avaxp.js | AI (source-diff): Long strings are hex-encoded AVAX blockchain transaction test fixtures; expected for this package. | ai | |
| source-diff | encoded-string-file:dist/test/resources/tx/importC.js | AI (source-diff): Long strings are hex-encoded AVAX blockchain transaction test fixtures. | ai | |
| source-diff | encoded-string-file:dist/test/resources/tx/importP.js | AI (source-diff): Long strings are hex-encoded AVAX blockchain transaction test fixtures. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): BitGo migrated publishing to bitgobot/GitHub Actions CI with SLSA provenance; consistent with org-wide CI/CD transition. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): bitgobot is BitGo's CI bot; addition is consistent with org-wide automation transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): bitgoaaron removed as part of BitGo's shift to CI-based publishing; not a hostile takeover. | ai | |
| provenance | no-provenance | AI (provenance): BitGo monorepo packages consistently lack Sigstore provenance; stable false positive for this package family. | ai |
v5.7.2
14 findingsAll previous maintainers (bitgoaaron) were replaced by new maintainers (bitgobot). This is a strong signal of a potential package hijack and requires careful review.
This version was published by a different npm account than previous versions on 2026-04-14. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 31 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.