@byteplus/veplayer
BytePlus Web Player
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:index.min.js | AI (source-diff): Minified UMD bundle of a video player SDK, not a dropper; no exfil destination shown. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Stale-for-1000+-days publisher change is inconsistent with account takeover per rule semantics. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-style maintainer list change consistent with BytePlus team account, publisher has strong track record. | ai | |
| source-diff | obfuscated-file:plugin/hlsjsPro.js | AI (source-diff): Minified UMD bundle output, not obfuscation; standard for HLS plugin. | ai | |
| source-diff | net-exec-file:plugin/hlsjsPro.js | AI (source-diff): Network+exec expected in a media player streaming plugin; bundled output. | ai | |
| source-diff | obfuscated-file:plugin/xgHls.js | AI (source-diff): Minified xgplayer HLS bundle, not obfuscation. | ai | |
| source-diff | encoded-string-file:plugin/hlsEncrypt.js | AI (source-diff): Long strings in bundled DRM/encrypt module; benign build artifact. | ai | |
| source-diff | encoded-string-file:index.min.js | AI (source-diff): Minified main bundle with banner; long strings are build output. | ai | |
| source-diff | encoded-string-file:plugin/XGVideo.js | AI (source-diff): Bundled xgplayer video module; benign minified output. | ai | |
| source-diff | encoded-string-file:esm/veplayer.biz.live.development.js | AI (source-diff): Bundled minified core-js/build artifacts, not injected malicious payload. | ai | |
| source-diff | encoded-string-file:esm/veplayer.biz.live.production.js | AI (source-diff): Minified bundle output, no material diff vs prior approved version. | ai | |
| source-diff | encoded-string-file:umd/veplayer.biz.live.development.js | AI (source-diff): Same bundled build artifact pattern as esm counterpart. | ai | |
| source-diff | encoded-string-file:umd/veplayer.biz.live.production.js | AI (source-diff): Minified bundle output, no material diff vs prior approved version. | ai | |
| source-diff | encoded-string-file:esm/veplayer.development.js | AI (source-diff): Encoded strings are core-js internals, consistent across releases. | ai | |
| source-diff | encoded-string-file:umd/veplayer.development.js | AI (source-diff): Encoded strings are core-js internals, consistent across releases. | ai | |
| source-diff | encoded-string-file:esm/veplayer.live.development.js | AI (source-diff): Bundled build artifact, not novel to this version. | ai | |
| source-diff | encoded-string-file:umd/veplayer.live.development.js | AI (source-diff): Bundled build artifact, not novel to this version. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established scoped official ByteDance package; missing metadata fields are stylistic, not spam. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 2.12.1 | 0 / 0 | |
| 2.12.0 | 0 / 0 | |
| 2.11.2 | 0 / 0 | |
| 2.11.1 | 0 / 0 | |
| 2.11.0 | 0 / 0 | |
| 2.10.3 | 0 / 0 | |
| 2.10.2 | 0 / 0 | |
| 2.10.1 | 0 / 0 | |
| 1.17.0 | 0 / 0 | |
| 1.16.0 | 0 / 0 | |
| 1.8.1 | 0 / 0 | |
| 1.8.0 | 0 / 0 | |
| 1.7.6 | 0 / 0 | |
| 1.7.5 | 0 / 0 | |
| 1.7.4 | 0 / 0 | |
| 1.7.2 | 0 / 0 | |
| 1.7.1 | 0 / 0 | |
| 1.7.0 | 0 / 0 | |
| 1.6.4 | 0 / 0 | |
| 1.6.3 | 0 / 0 | |
| 1.1.2 | 0 / 27 | |
| 1.1.1 | 0 / 27 | |
| 1.1.0 | 0 / 27 |
v2.11.2
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.3
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-31. It has since remained available on npm for 905 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.8.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-25. It has since remained available on npm for 911 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-12. It has since remained available on npm for 924 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-11. It has since remained available on npm for 925 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-04. It has since remained available on npm for 932 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-12-15. It has since remained available on npm for 952 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-12-15. It has since remained available on npm for 952 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.7.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-11-07. It has since remained available on npm for 990 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-10-20. It has since remained available on npm for 1008 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-10-12. It has since remained available on npm for 1016 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (chenyongjin) than the most recent previously approved version (xiongxiong.001) on 2023-05-24, but chenyongjin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.