← Home

@bitgo/secp256k1

37
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

louib-bitgobitgobot

Keywords

bitgoeccbip32musigmusig2

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/src/bip32utils.js AI (source-diff): TS compiler output boilerplate, not obfuscation; implements documented bip32 signing feature. ai
source-diff obfuscated-file:./dist/src/index.js AI (source-diff): Compiled TS output with long lines, not obfuscation; no malicious behavior in sample. ai
maintainer-change maintainer-added AI (maintainer-change): Known BitGo maintainer, manual publish matches prior approved maintainer list. ai
dependencies unvetted-dep:bitcoinjs-message AI (dependencies): Aliased to @bitgo-forks/bitcoinjs-message, a BitGo-controlled fork; consistent with BitGo's ecosystem pattern. ai
dependencies unvetted-dep:@brandonblack/musig AI (dependencies): Known MuSig2 implementation used by BitGo for secp256k1 musig2 support; stable dependency for this package. ai

Versions (showing 37 of 37)

Version Deps Published
1.11.0 8 / 1
1.10.0 8 / 1
1.9.0 8 / 1
1.8.0 6 / 1
1.7.0 6 / 1
1.5.0 6 / 1
1.4.0 6 / 1
1.3.3 6 / 1
1.3.2 6 / 1
1.3.1 6 / 2
1.3.0 6 / 2
1.2.25 6 / 2
1.2.24 6 / 2
1.2.23 6 / 2
1.2.22 6 / 2
1.2.21 6 / 2
1.2.20 6 / 2
1.2.19 6 / 2
1.2.18 6 / 2
1.2.17 6 / 2
1.2.16 6 / 2
1.2.15 6 / 2
1.2.14 6 / 2
1.2.13 6 / 2
1.2.12 6 / 2
1.2.11 6 / 2
1.2.10 6 / 2
1.2.8 6 / 2
1.2.7 6 / 2
1.2.6 6 / 2
1.2.5 6 / 2
1.2.3 6 / 2
1.2.2 6 / 2
1.2.1 6 / 2
1.2.0 6 / 2
1.1.0 6 / 2
1.0.1 6 / 2

v1.10.0

2 findings
HIGH New obfuscated file: dist/src/bip32utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

2 findings
HIGH New obfuscated file: dist/src/bip32utils.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.0

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: zahin-mohammad → pengyuc_bitgo (on 2024-02-06, unremoved on npm for 896d) provenance

This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-02-06. It has since remained available on npm for 896 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.25

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: zahin-mohammad → pengyuc_bitgo (on 2024-01-30, unremoved on npm for 903d) provenance

This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-01-30. It has since remained available on npm for 903 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.24

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2024-01-26, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-26, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.23

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2024-01-26, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-26, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.22

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2024-01-25, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-25, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.21

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2024-01-22, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-22, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.20

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2024-01-09, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2024-01-09, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.19

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: zahin-mohammad → pengyuc_bitgo (on 2024-01-03, unremoved on npm for 930d) provenance

This version was published by a different npm account (pengyuc_bitgo) than the most recent previously approved version (zahin-mohammad) on 2024-01-03. It has since remained available on npm for 930 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.18

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-12-18, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-18, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.17

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-12-12, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-12, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.16

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-12-09, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-09, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.15

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-12-05, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-12-05, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.14

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-11-28, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-28, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.13

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-11-24, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-24, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.12

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-11-17, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-17, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.11

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-11-13, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-13, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.10

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-11-13, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-11-13, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.8

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-10-20, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-10-20, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.7

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-10-18, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-10-18, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.6

3 findings
HIGH New obfuscated file: ./dist/src/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → alebusse (on 2023-09-25, known maintainer) provenance

This version was published by a different npm account (alebusse) than the most recent previously approved version (zahin-mohammad) on 2023-09-25, but alebusse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mmcshinsky-bitgo → zahin-mohammad (on 2023-09-01, known maintainer) provenance

This version was published by a different npm account (zahin-mohammad) than the most recent previously approved version (mmcshinsky-bitgo) on 2023-09-01, but zahin-mohammad is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.2.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zahin-mohammad → mmcshinsky-bitgo (on 2023-08-04, known maintainer) provenance

This version was published by a different npm account (mmcshinsky-bitgo) than the most recent previously approved version (zahin-mohammad) on 2023-08-04, but mmcshinsky-bitgo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.