← Home

@cipherstash/protect-ffi

> [!IMPORTANT] > If you are looking to implement this package into your application please use the official [protect package](https://github.com/cipherstash/protectjs).

33
Versions
ISC
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cs_lindsaydrew_cipherstashjames-sadlerdan-drapercs-zcjbrewertobyhede

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/wasm/protect_ffi_bg.js AI (source-diff): wasm-bindgen generated glue code, not network+exec malware. ai
source-diff obfuscated-file:dist/wasm/protect_ffi_inline.js AI (source-diff): Base64-inlined wasm binary from documented inline-wasm.mjs build script. ai
npm-metadata bundled-binaries AI (npm-metadata): Wasm binary is the compiled Rust FFI core, documented build output for this native binding package. ai
source-diff source-size-tripled AI (source-diff): Size increase matches newly added wasm build scripts, not injected payload. ai
source-diff large-new-source-files AI (source-diff): New files are wasm build output tied to added build:wasm scripts. ai
provenance publisher-changed AI (provenance): cs-zcjbrewer is a CipherStash org account with 37 approved packages; consistent with internal maintainer rotation. ai

Versions (showing 33 of 33)

Version Deps Published
0.29.0 1 / 6
0.28.0 1 / 6
0.27.0 1 / 6
0.26.0 1 / 6
0.25.0 1 / 6
0.24.0 1 / 6
0.23.0 1 / 6
0.22.0 1 / 6
0.21.4 1 / 6
0.21.3 1 / 6
0.21.2 1 / 6
0.21.1 1 / 6
0.21.0 1 / 6
0.20.2 1 / 5
0.20.1 1 / 5
0.20.0 1 / 5
0.19.0 1 / 5
0.18.1 1 / 5
0.17.1 1 / 5
0.17.0 1 / 5
0.16.1 1 / 5
0.16.0 1 / 5
0.15.0 1 / 5
0.14.2 1 / 5
0.14.1 1 / 5
0.14.0 1 / 5
0.12.0 1 / 4
0.11.0 1 / 4
0.10.0 1 / 4
0.9.0 1 / 4
0.8.0 1 / 4
0.7.0 1 / 4
0.5.4 1 / 4

v0.29.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/wasm/protect_ffi_bg.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: cs-zcjbrewer → GitHub Actions (on 2026-07-09) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.

v0.28.0

5 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/wasm/protect_ffi_bg.wasm

HIGH New file with network + code execution: dist/wasm/protect_ffi_bg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/wasm/protect_ffi_inline.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: cs-zcjbrewer → GitHub Actions (on 2026-07-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-07-08. This could indicate a legitimate maintainer transition or an account compromise.

v0.27.0

4 findings
HIGH New file with network + code execution: dist/wasm/protect_ffi_bg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/wasm/protect_ffi_inline.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: cs-zcjbrewer → GitHub Actions (on 2026-07-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-07-04. This could indicate a legitimate maintainer transition or an account compromise.

v0.26.0

4 findings
HIGH New file with network + code execution: dist/wasm/protect_ffi_bg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/wasm/protect_ffi_inline.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: cs-zcjbrewer → GitHub Actions (on 2026-06-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-06-08. This could indicate a legitimate maintainer transition or an account compromise.

v0.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.