← Home

@contentful/live-preview

Preview SDK for both the field tagging connection + live content updates

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

it-internalwhydah-gallycontentful-ecosystemmichaelpearce

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/src-CazfDf20.cjs AI (source-diff): Bundled SDK output; net+exec are library primitives, no hostile target. ai
source-diff net-exec-file:dist/src-gOMxjmYt.js AI (source-diff): Rolldown ESM bundle of the same SDK; benign build artifact. ai
source-diff obfuscated-file:dist/src-CazfDf20.cjs AI (source-diff): Rolldown minified bundle, not obfuscation; content-source-maps zero-width encoding is expected. ai
source-diff obfuscated-file:dist/src-VbuEYWL_.cjs AI (source-diff): Bundled vite/rolldown output for content-source-maps; minified not obfuscated. ai
source-diff net-exec-file:dist/src-e13kLMf5.js AI (source-diff): Bundle artifact of first-party SDK; no hostile net+exec behavior. ai
source-diff net-exec-file:dist/src-VbuEYWL_.cjs AI (source-diff): Bundle artifact of first-party SDK; no hostile net+exec behavior. ai
source-diff obfuscated-file:dist/index-y_tTfYG2.cjs AI (source-diff): Vite-bundled content-source-maps encoding; benign build output for this SDK. ai
source-diff net-exec-file:dist/index-C5Din3Pu.js AI (source-diff): Bundled SDK code, no hostile fetch/exec target; matches stated live-preview function. ai
source-diff net-exec-file:dist/index-y_tTfYG2.cjs AI (source-diff): Bundled SDK code, no hostile fetch/exec target; matches stated live-preview function. ai
source-diff net-exec-file:dist/index-CGky0iBz.js AI (source-diff): Same benign minified SDK code; no fetched-payload execution. ai
source-diff net-exec-file:dist/index-BR1-7WxZ.cjs AI (source-diff): Encode/decode + URL parsing in minified SDK output; no dropper behavior. ai
source-diff obfuscated-file:dist/index-BR1-7WxZ.cjs AI (source-diff): Minified bundle of Contentful's Unicode edit-tag encoding, not obfuscated malware. ai
source-diff net-exec-file:dist/index-C9sCzSmY.cjs AI (source-diff): Bundled SDK build output; no dropper behavior, benign encoder logic. ai
source-diff obfuscated-file:dist/index-C9sCzSmY.cjs AI (source-diff): Minified bundle of Contentful invisible-char edit-info encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-BSy_7kqK.js AI (source-diff): Same bundled SDK, ESM variant; benign. ai
source-diff net-exec-file:dist/index-DSzvrru9.cjs AI (source-diff): Unicode-codepoint encode/decode + URL parsing flagged as net+exec; benign SDK logic. ai
source-diff net-exec-file:dist/index-CL7aPN3X.js AI (source-diff): Same benign encode/decode logic in ESM build variant. ai
source-diff obfuscated-file:dist/index-DSzvrru9.cjs AI (source-diff): Minified build output of invisible-char edit-info encoding, not obfuscated malware. ai
source-diff net-exec-file:dist/index-Dig1r0E4.js AI (source-diff): Bundled SDK; encoding logic, no dropper behavior/hostile destination. ai
source-diff obfuscated-file:dist/index-V_-n4X9G.cjs AI (source-diff): Minified bundle output of edit-tag Unicode encoder; not true obfuscation. ai
source-diff net-exec-file:dist/index-V_-n4X9G.cjs AI (source-diff): Bundled SDK; encoding logic, no dropper behavior/hostile destination. ai
source-diff obfuscated-file:dist/index-ClETh9GB.cjs AI (source-diff): Minified bundler output of documented Unicode edit-info encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-r02ppj-U.js AI (source-diff): Same live-preview bundle logic; benign network/parse patterns. ai
source-diff net-exec-file:dist/index-ClETh9GB.cjs AI (source-diff): URL/JSON parsing in bundle, no fetched-code execution or exfil target. ai
source-diff obfuscated-file:dist/index-Bnfxvhih.cjs AI (source-diff): Minified build output implementing Contentful's invisible-char content tagging; stable per release. ai
source-diff net-exec-file:dist/index-Bnfxvhih.cjs AI (source-diff): Encoding/decoding SDK logic in bundled dist, no hostile fetch+exec destination. ai
source-diff net-exec-file:dist/index-BC4rIK6w.js AI (source-diff): Same SDK encoding logic in ESM bundle; benign for this package. ai
source-diff obfuscated-file:dist/index-BJ6b29Wf.cjs AI (source-diff): Minified bundle output implementing documented zero-width edit-tag encoding; not obfuscation. ai
source-diff net-exec-file:dist/index-Z8B07jlJ.js AI (source-diff): Same bundled SDK output, ESM variant; benign live-preview encoding. ai
source-diff net-exec-file:dist/index-BJ6b29Wf.cjs AI (source-diff): Bundled SDK code; no hostile fetch/exec target, encoding logic only. ai
source-diff net-exec-file:dist/index-BcdXI32C.cjs AI (source-diff): Bundled build output for official Contentful SDK; no hostile destination. ai
source-diff net-exec-file:dist/index-BsEw_DeU.js AI (source-diff): Same bundled SDK logic, ESM variant; benign. ai
source-diff obfuscated-file:dist/index-BcdXI32C.cjs AI (source-diff): Bundled minified SDK output; invisible-char encoding is core live-preview function, not obfuscation. ai
source-diff net-exec-file:dist/src-Dy2rqqUZ.cjs AI (source-diff): Content-source metadata encoder, not a dropper; benign SDK feature. ai
source-diff obfuscated-file:dist/src-Dy2rqqUZ.cjs AI (source-diff): Minified rolldown bundle of the SDK's zero-width codepoint encoder; not obfuscation. ai
source-diff net-exec-file:dist/src-BNMF2B9A.js AI (source-diff): Readable rolldown-bundled SDK output; same encoder logic, no hostile target. ai
source-diff net-exec-file:dist/index-BXf_ZeeV.cjs AI (source-diff): Minified SDK bundle; net+eval heuristic false positive on official Contentful build output. ai
source-diff net-exec-file:dist/index-RrXZ97Pr.js AI (source-diff): Same minified SDK bundle; benign build output from official org. ai
source-diff obfuscated-file:dist/index-BXf_ZeeV.cjs AI (source-diff): Bundled dist; zero-width Unicode content-source-map encoder, not obfuscated payload. ai
source-diff net-exec-file:dist/index-BcE3i9XZ.cjs AI (source-diff): Long-line heuristic on legit bundled encoder; no real dropper behavior. ai
source-diff net-exec-file:dist/index-3u4eKz-s.js AI (source-diff): Same encoder in JS build output; benign for this package. ai
source-diff obfuscated-file:dist/index-BcE3i9XZ.cjs AI (source-diff): Minified bundle of documented invisible-char content-source-map encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-BdQ-t5j7.cjs AI (source-diff): Minified SDK bundle; no fetched-binary exec or exfil destination. ai
source-diff net-exec-file:dist/index-DVTW8xJk.js AI (source-diff): Minified SDK bundle; benign build output. ai
source-diff obfuscated-file:dist/index-BdQ-t5j7.cjs AI (source-diff): Vite-bundled content-source-maps unicode encoder; not obfuscation. ai
source-diff net-exec-file:dist/src-C7cXhlOc.cjs AI (source-diff): Bundled SDK; content-tagging codec, no hostile fetch/exec destination. ai
source-diff net-exec-file:dist/src-DpXJbZnK.js AI (source-diff): Bundled SDK; content-tagging codec, no hostile fetch/exec destination. ai
source-diff obfuscated-file:dist/src-C7cXhlOc.cjs AI (source-diff): Rolldown-bundled minified output of official SDK; long lines are build artifact, not obfuscation. ai
source-diff net-exec-file:dist/index-ByITfjmi.cjs AI (source-diff): Bundled SDK output; net+exec heuristic misfires on legit live-preview code. ai
source-diff net-exec-file:dist/index-Bb-hmh7b.js AI (source-diff): Same bundled SDK; benign network/postMessage usage for live preview. ai
source-diff obfuscated-file:dist/index-ByITfjmi.cjs AI (source-diff): Unicode zero-width edit-info encoder from @contentful/content-source-maps; bundled dist, not obfuscation. ai
source-diff net-exec-file:dist/index-Cc8lUfSx.cjs AI (source-diff): Bundled SDK dist; encoder/URL-parse pattern, no dropper behavior. ai
source-diff net-exec-file:dist/index-CWfya0MQ.js AI (source-diff): Same bundled encoder logic in ESM twin; benign. ai
source-diff obfuscated-file:dist/index-Cc8lUfSx.cjs AI (source-diff): Content-source-maps invisible-char encoder; long lines are bundled Vite output, not obfuscation. ai
source-diff net-exec-file:dist/index-jFZSkMpB.cjs AI (source-diff): Bundled SDK output; no hostile fetch/exec target, first-party Contentful preview logic. ai
source-diff obfuscated-file:dist/index-jFZSkMpB.cjs AI (source-diff): Zero-width-char edit-tag encoder in bundled dist; recurring build artifact for this SDK. ai
source-diff net-exec-file:dist/index-DONIKAeF.js AI (source-diff): Same bundled first-party live-preview code; benign network+JSON logic. ai
source-diff obfuscated-file:dist/index-BcOK2j59.cjs AI (source-diff): Unicode-codepoint content-tagging encoder in bundled dist; false-positive for this SDK's core function. ai
source-diff net-exec-file:dist/index-BcOK2j59.cjs AI (source-diff): Bundled SDK output; net+exec heuristic misfires on live-preview encoder, no hostile target. ai
source-diff net-exec-file:dist/index-Cu3sKETn.js AI (source-diff): Same bundled encoder in ESM variant; benign build artifact. ai
source-diff net-exec-file:dist/index-Ca8gh4ji.js AI (source-diff): Bundled SDK code; net+exec heuristic on official Contentful dist bundle. ai
source-diff net-exec-file:dist/index-FNA3PyQV.cjs AI (source-diff): Bundled SDK code; net+exec heuristic on official Contentful dist bundle. ai
source-diff obfuscated-file:dist/index-FNA3PyQV.cjs AI (source-diff): Minified bundle output; zero-width-char edit-tag encoding, not obfuscation. ai
source-diff obfuscated-file:dist/index-CxHJ3uPI.cjs AI (source-diff): Minified build output of Contentful's zero-width-char content-source-map encoder, not obfuscated malware. ai
source-diff net-exec-file:dist/index-1ElyYUDu.js AI (source-diff): Same bundled encoder, ESM variant; benign first-party SDK code. ai
source-diff net-exec-file:dist/index-CxHJ3uPI.cjs AI (source-diff): Bundled SDK output; net+exec heuristic on legit live-preview encoder, no hostile destination. ai
source-diff obfuscated-file:dist/index-C8Wl5Q9a.cjs AI (source-diff): Minified bundle of Contentful's Unicode edit-info encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-C8Wl5Q9a.cjs AI (source-diff): Minified SDK bundle; codepoint encode/decode, no fetched-code execution. ai
source-diff net-exec-file:dist/index-BGDSxxFC.js AI (source-diff): Same SDK bundle, ESM variant; benign live-preview encoding logic. ai
source-diff net-exec-file:dist/index-CL1SAhuh.js AI (source-diff): Same bundled ESM output as cjs sibling; legitimate SDK behavior. ai
source-diff net-exec-file:dist/index-jkJnb17V.cjs AI (source-diff): Bundled SDK; net+exec heuristic on legit content-source-map/live-update code. ai
source-diff obfuscated-file:dist/index-jkJnb17V.cjs AI (source-diff): Invisible-Unicode content-source-map encoder, minified build output; benign for this SDK. ai
source-diff net-exec-file:dist/index-D7yy0vxo.js AI (source-diff): ESM sibling of same bundled build output; benign. ai
source-diff net-exec-file:dist/index-l7NjQcXz.cjs AI (source-diff): Bundled SDK build; no dropper behavior, encode/decode helpers only. ai
source-diff obfuscated-file:dist/index-l7NjQcXz.cjs AI (source-diff): Vite build output of content-source-maps encoder; minified not obfuscated. ai
source-diff obfuscated-file:dist/src-C9hMpwLR.cjs AI (source-diff): Minified rolldown output, not true obfuscation. ai
source-diff net-exec-file:dist/src-CaS_Z6p_.js AI (source-diff): Same rolldown bundle, .js variant; build artifact. ai
source-diff net-exec-file:dist/src-C9hMpwLR.cjs AI (source-diff): Rolldown bundle output for live-preview encoding feature; not a dropper. ai
source-diff net-exec-file:dist/index-uwm6IWYN.cjs AI (source-diff): Bundled SDK build; net+decode is legit source-map fetch/parse. ai
source-diff net-exec-file:dist/index-C17nSolv.js AI (source-diff): Same bundled SDK logic in ESM output; benign. ai
source-diff obfuscated-file:dist/index-uwm6IWYN.cjs AI (source-diff): Minified Vite bundle of content-source-maps encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-BBFPdhH0.cjs AI (source-diff): Bundled SDK output; no hostile fetch/exec, first-party live-preview logic. ai
source-diff obfuscated-file:dist/index-BBFPdhH0.cjs AI (source-diff): Minified bundle of Contentful's Unicode edit-info encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-xXJl9JUq.js AI (source-diff): Same bundled SDK code, benign build artifact. ai
source-diff net-exec-file:dist/index-CVRmqoLq.cjs AI (source-diff): Minified bundle heuristic FP; no hostile network target in legit Contentful SDK. ai
source-diff obfuscated-file:dist/index-CVRmqoLq.cjs AI (source-diff): Bundled/minified SDK build output, not obfuscation; regenerated each release. ai
source-diff net-exec-file:dist/index-D4vH9yNi.js AI (source-diff): Same bundled build FP across ESM/CJS outputs. ai
source-diff obfuscated-file:dist/index-bmsQ42uB.cjs AI (source-diff): Bundled dist with Unicode edit-info encoding tables; benign minified SDK output. ai
source-diff net-exec-file:dist/index-bmsQ42uB.cjs AI (source-diff): Net+exec heuristic on bundled SDK; no hostile destination, standard live-preview encoding logic. ai
source-diff net-exec-file:dist/index-BWwcdB3_.js AI (source-diff): Same bundled SDK code in ESM form; benign build output. ai
source-diff net-exec-file:dist/index-DBm-yZjK.cjs AI (source-diff): Zero-width encode/decode logic, no fetched-payload execution; false positive in minified SDK dist. ai
source-diff obfuscated-file:dist/index-DBm-yZjK.cjs AI (source-diff): Minified dist of the live-preview Unicode edit-info encoder; benign build output. ai
source-diff net-exec-file:dist/index-D41C7B6Q.js AI (source-diff): Same encoder in ESM dist; no dropper behavior. ai
source-diff net-exec-file:dist/index-Btv3iL1F.js AI (source-diff): Same bundled SDK content in unminified form; benign. ai
source-diff net-exec-file:dist/index-By3Rqgs3.cjs AI (source-diff): Bundled SDK output; no fetched-binary execution, benign codepoint/JSON logic. ai
source-diff obfuscated-file:dist/index-By3Rqgs3.cjs AI (source-diff): Minified bundle of Contentful's zero-width-char edit-info encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-CAESNJuv.cjs AI (source-diff): Codepoint-encoding logic in vite bundle; no fetched-binary execution or exfil. ai
source-diff net-exec-file:dist/index-CChN__FL.js AI (source-diff): Same encoder logic in ESM bundle; benign. ai
source-diff obfuscated-file:dist/index-CAESNJuv.cjs AI (source-diff): Bundled content-source-maps invisible-Unicode encoder; benign minified build output. ai
source-diff obfuscated-file:dist/index-BgJYYYwy.cjs AI (source-diff): Bundled invisible-char encoder for live-preview edit info; not obfuscation. ai
source-diff net-exec-file:dist/index-BgJYYYwy.cjs AI (source-diff): SDK bundle; no dropper behavior, benign encode/decode + fetch. ai
source-diff net-exec-file:dist/index-CCtUt9Tt.js AI (source-diff): Same SDK bundle content; benign live-preview networking. ai
source-diff obfuscated-file:dist/index-CzzyreLd.cjs AI (source-diff): Bundled dist implementing content-source-maps invisible-char encoding; long lines are minified build output. ai
source-diff net-exec-file:dist/index-CzzyreLd.cjs AI (source-diff): Bundled SDK dist; no dropper behavior, matches stated live-preview function. ai
source-diff net-exec-file:dist/index-D-6iR_jP.js AI (source-diff): ESM twin of same bundled dist; benign SDK build output. ai
source-diff net-exec-file:dist/index-CKnNtMVx.js AI (source-diff): Bundled first-party live-preview code; no hostile net+exec behavior. ai
source-diff obfuscated-file:dist/index-BBQr5qrL.cjs AI (source-diff): Vite bundle output of content-source-maps Unicode encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-BBQr5qrL.cjs AI (source-diff): Bundled first-party live-preview code; no hostile net+exec behavior. ai
source-diff obfuscated-file:dist/index-55xaTOC0.cjs AI (source-diff): Vite-bundled content-source-maps Unicode encoder; benign build output. ai
source-diff net-exec-file:dist/index-55xaTOC0.cjs AI (source-diff): Bundled SDK output; no fetched-binary/inline-eval behavior in sample. ai
source-diff net-exec-file:dist/index-BiG5czIX.js AI (source-diff): Bundled SDK output; same encoder logic, benign. ai
source-diff net-exec-file:dist/index-BWioMUj8.js AI (source-diff): Same SDK codec bundle, ESM variant; benign. ai
source-diff net-exec-file:dist/index-DjhlJY6b.cjs AI (source-diff): Encode/decode + fetch is the SDK's live-preview core; benign for this package. ai
source-diff obfuscated-file:dist/index-DjhlJY6b.cjs AI (source-diff): Vite-bundled content-source-maps codec (invisible-char encoding), not obfuscated malware. ai
source-diff net-exec-file:dist/index-CkU3FxlH.js AI (source-diff): Vite bundle output; benign content-source-maps codec. ai
source-diff obfuscated-file:dist/index-DNJKuG9c.cjs AI (source-diff): Minified vite build, not true obfuscation. ai
source-diff net-exec-file:dist/index-DNJKuG9c.cjs AI (source-diff): Vite bundle output; encoding logic, no fetched-code execution. ai
source-diff net-exec-file:dist/index-Cwoaqxkt.js AI (source-diff): Bundled build output; no dropper behavior, benign for this package. ai
source-diff net-exec-file:dist/index-CLlmqir1.cjs AI (source-diff): Bundled build output; no dropper behavior, benign for this package. ai
source-diff obfuscated-file:dist/index-CLlmqir1.cjs AI (source-diff): Vite-minified dist of the source-maps encoder; recurs every release. ai
source-diff net-exec-file:dist/index-BJjjK8VY.js AI (source-diff): Same bundled SDK output in ESM form; benign encoder logic. ai
source-diff net-exec-file:dist/index-BZ8d8cOE.cjs AI (source-diff): Bundled SDK output; codepoint/URL logic misreads as net+exec, no hostile target. ai
source-diff obfuscated-file:dist/index-BZ8d8cOE.cjs AI (source-diff): Vite-bundled dist for content-source-maps zero-width encoder; minified, not obfuscated. ai
source-diff obfuscated-file:dist/index-CRqler0W.cjs AI (source-diff): Minified Vite output of content-source-maps Unicode encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-CRqler0W.cjs AI (source-diff): Encoder/decoder logic; no dropper behavior, benign build artifact. ai
source-diff net-exec-file:dist/index-BH_OaR7W.js AI (source-diff): Same encoder logic in ESM build output; benign. ai
source-diff obfuscated-file:dist/index-C2Z6VW0_.cjs AI (source-diff): Minified bundle output of official Contentful SDK; not true obfuscation. ai
source-diff net-exec-file:dist/index-C2Z6VW0_.cjs AI (source-diff): Bundler heuristic FP on legit SDK dist; no hostile destination. ai
source-diff net-exec-file:dist/index-CWmP-2HO.js AI (source-diff): Bundler heuristic FP on legit SDK dist; no hostile destination. ai
source-diff net-exec-file:dist/index-vbrZWNn8.js AI (source-diff): Same bundled SDK logic in ESM output; benign. ai
source-diff net-exec-file:dist/index-CFutq1Xd.cjs AI (source-diff): Minified SDK bundle; codepoint encode/decode, no hostile fetch+exec. ai
source-diff obfuscated-file:dist/index-CFutq1Xd.cjs AI (source-diff): Vite-minified build output; content-source-map Unicode encoding, not obfuscation. ai
source-diff net-exec-file:dist/index-incI5N0z.js AI (source-diff): Same source-maps encoder in ESM bundle; no fetched-code execution. ai
source-diff net-exec-file:dist/index-VAB_rHFi.cjs AI (source-diff): JSON.parse of decoded edit-info, not code exec; benign SDK encoder in bundled output. ai
source-diff obfuscated-file:dist/index-VAB_rHFi.cjs AI (source-diff): Vite-bundled content-source-maps invisible-char encoder; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/index-DYPyK3-e.cjs AI (source-diff): Bundled SDK; encode/decode logic, no fetched-binary execution or hostile endpoint. ai
source-diff net-exec-file:dist/index-D9IzsERL.js AI (source-diff): ESM sibling of same bundled SDK output; benign. ai
source-diff obfuscated-file:dist/index-DYPyK3-e.cjs AI (source-diff): Vite build output; long lines from Unicode codepoint tables for content-source-maps encoding, not obfuscation. ai
source-diff net-exec-file:dist/index-DGlupfJI.js AI (source-diff): Same bundled SDK logic in ESM output; benign. ai
source-diff net-exec-file:dist/index-BnLyXVi4.cjs AI (source-diff): Bundled SDK code; no fetched-code execution, just codepoint encode/decode. ai
source-diff obfuscated-file:dist/index-BnLyXVi4.cjs AI (source-diff): Minified Vite bundle of source-maps Unicode encoder; benign build output. ai
source-diff obfuscated-file:dist/index-CsORnv_K.cjs AI (source-diff): Minified dist output of Contentful's zero-width encoding logic, not obfuscation. ai
source-diff net-exec-file:dist/index-C7uBYwmL.js AI (source-diff): Same benign encoding logic in unminified build variant. ai
source-diff net-exec-file:dist/index-CsORnv_K.cjs AI (source-diff): Codepoint encoding/JSON.parse pattern, no fetched-binary exec; benign SDK code. ai
source-diff net-exec-file:dist/index-DCK6fjIR.cjs AI (source-diff): Bundled SDK; net+JSON.parse patterns, no dropper/loader behavior. ai
source-diff net-exec-file:dist/index-D9gxuvRN.js AI (source-diff): Same bundled SDK output; benign live-preview functionality. ai
source-diff obfuscated-file:dist/index-DCK6fjIR.cjs AI (source-diff): Bundled dist implementing Contentful's zero-width-char edit-info encoding; not obfuscation. ai
source-diff net-exec-file:dist/index-C8Q2UOzz.cjs AI (source-diff): Bundled SDK output; net+exec heuristic on legit live-preview messaging code. ai
source-diff net-exec-file:dist/index-CGT_r_Uh.js AI (source-diff): Bundled SDK output; benign build artifact. ai
source-diff obfuscated-file:dist/index-C8Q2UOzz.cjs AI (source-diff): Minified vite bundle; Unicode-codepoint tables are the SDK's source-map encoding, not obfuscation. ai
source-diff net-exec-file:dist/index-CFI3n_kp.cjs AI (source-diff): Bundled SDK output; no dropper behavior, just codepoint encode/decode logic. ai
source-diff net-exec-file:dist/index-6a60Bhmi.js AI (source-diff): Same bundled SDK source, unminified ESM variant; benign. ai
source-diff obfuscated-file:dist/index-CFI3n_kp.cjs AI (source-diff): Minified bundle of Unicode edit-info encoder; false-positive long-line trigger. ai
source-diff net-exec-file:dist/index-BYZWrixv.cjs AI (source-diff): URL parsing + JSON decode in bundled SDK, no fetched-code execution. ai
source-diff net-exec-file:dist/index-Bw-_OeWY.js AI (source-diff): Same benign encoder, ESM build output of official SDK. ai
source-diff obfuscated-file:dist/index-BYZWrixv.cjs AI (source-diff): Vite-bundled content-source-maps invisible-char encoder; minified, not obfuscated malware. ai
source-diff net-exec-file:dist/index-JyAyuKLS.js AI (source-diff): Bundled SDK output; no hostile fetch/exec target, stable FP. ai
source-diff obfuscated-file:dist/index-DJTHLeG4.cjs AI (source-diff): Invisible-char content-source-map encoder; minified vite output, benign for this package. ai
source-diff net-exec-file:dist/index-DJTHLeG4.cjs AI (source-diff): Bundled SDK output; no hostile fetch/exec target, stable FP. ai
source-diff net-exec-file:dist/index-kjD1sBMe.js AI (source-diff): Build-bundle heuristic false positive in minified dist. ai
source-diff obfuscated-file:dist/index-DahRa9SD.cjs AI (source-diff): Vite-minified dist output of the SDK's encoding logic; not obfuscation. ai
source-diff net-exec-file:dist/index-DahRa9SD.cjs AI (source-diff): Build-bundle heuristic false positive in minified dist. ai
source-diff obfuscated-file:dist/index-CPUcM0Va.cjs AI (source-diff): Bundled dist; long lines are Contentful's Unicode edit-info encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-CPUcM0Va.cjs AI (source-diff): Minified bundle; URL/decode heuristics misfire on legit SDK encoding logic. ai
source-diff net-exec-file:dist/index-DxAnX9OZ.js AI (source-diff): Same bundled SDK output; no fetched-binary exec, benign. ai
source-diff net-exec-file:dist/index-CqF6bdnZ.js AI (source-diff): Minified SDK bundle; live-preview needs network calls, no hostile destination. ai
source-diff obfuscated-file:dist/index-D_fGxCsx.cjs AI (source-diff): Vite-bundled minified output implementing content-source-map encoding; benign build artifact. ai
source-diff net-exec-file:dist/index-D_fGxCsx.cjs AI (source-diff): Minified SDK bundle; no fetched-binary exec or exfil target, expected build output. ai
source-diff obfuscated-file:dist/index-CQcAUn0s.cjs AI (source-diff): Minified Vite bundle output, not obfuscation; benign build artifact for this SDK. ai
source-diff net-exec-file:dist/index-BrCbu6Ek.js AI (source-diff): Bundled ESM build output; same benign SDK logic. ai
source-diff net-exec-file:dist/index-CQcAUn0s.cjs AI (source-diff): Bundled build output; content-source-map encoding, no hostile fetch/exec target. ai
source-diff obfuscated-file:dist/index-CFy3VtL5.cjs AI (source-diff): Minified vite output of content-source-maps codepoint encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-Br2Z3Job.js AI (source-diff): Bundled SDK build; encoding logic, no dropper behavior. ai
source-diff net-exec-file:dist/index-CFy3VtL5.cjs AI (source-diff): Bundled SDK build; encoding logic, no dropper behavior. ai
source-diff obfuscated-file:dist/index-DjrB8Q1r.cjs AI (source-diff): Vite-minified dist output; encoder uses zero-width Unicode tables, not obfuscation. ai
source-diff net-exec-file:dist/index-DchkmM45.js AI (source-diff): ESM twin of the cjs build output; same benign SDK logic. ai
source-diff net-exec-file:dist/index-DjrB8Q1r.cjs AI (source-diff): Minified build of live-preview SDK; net+URL parsing is normal SDK function, no fetched-code execution. ai
source-diff net-exec-file:dist/index-vHo10KOP.js AI (source-diff): Same bundled SDK content in ESM form; benign build artifact. ai
source-diff obfuscated-file:dist/index-CGsLI5ED.cjs AI (source-diff): Minified Vite bundle output, not obfuscation; standard for this build pipeline. ai
source-diff net-exec-file:dist/index-CGsLI5ED.cjs AI (source-diff): Bundled SDK code; unicode edit-info encoding, no hostile fetch/exec destination. ai
source-diff obfuscated-file:dist/index-D0tGS6-9.cjs AI (source-diff): Vite-bundled minified output; zero-width encoding is documented content-source-maps feature. ai
source-diff net-exec-file:dist/index-DTAeTYjK.js AI (source-diff): Build bundle for first-party SDK; no hostile destination. ai
source-diff net-exec-file:dist/index-D0tGS6-9.cjs AI (source-diff): Build bundle for first-party SDK; no hostile destination. ai
source-diff net-exec-file:dist/index-BRM1evsg.js AI (source-diff): Same bundled SDK build; benign encoder, no dropper behavior. ai
source-diff net-exec-file:dist/index-DbHtArXe.cjs AI (source-diff): Bundled SDK code; encoder logic, no fetched-payload execution. ai
source-diff obfuscated-file:dist/index-DbHtArXe.cjs AI (source-diff): Vite-bundled minified output of content-source-maps encoder; not obfuscation. ai
source-diff net-exec-file:dist/src-D9U4PMO2.cjs AI (source-diff): Content-source-map Unicode encoding + bundle runtime; no hostile fetch/exec target. ai
source-diff obfuscated-file:dist/src-D9U4PMO2.cjs AI (source-diff): Rolldown-bundled minified output; long lines are build artifact, not obfuscation. ai
source-diff net-exec-file:dist/src-DxKlL-rp.js AI (source-diff): Same rolldown build output; benign SDK functionality. ai
source-diff obfuscated-file:dist/index-DPa35cVv.cjs AI (source-diff): Invisible-Unicode content-source-maps encoder in Vite bundle output; stable feature of this SDK. ai
source-diff net-exec-file:dist/index-DPa35cVv.cjs AI (source-diff): Unicode encode/decode round-trip, not net+exec dropper; bundled build artifact. ai
source-diff net-exec-file:dist/index-DIczhOoz.js AI (source-diff): Same encoder logic in ESM bundle; benign build output. ai
source-diff net-exec-file:dist/index-DOONljbN.js AI (source-diff): Bundled SDK output; same heuristic on ESM build, benign. ai
source-diff net-exec-file:dist/index-WfjujYGF.cjs AI (source-diff): Bundled SDK output; net+eval heuristic on minified live-preview code, no hostile destination. ai
source-diff obfuscated-file:dist/index-WfjujYGF.cjs AI (source-diff): Vite-bundled minified output implementing zero-width Unicode encoder; benign for this SDK. ai
source-diff obfuscated-file:dist/index-B_KvkeRr.cjs AI (source-diff): Vite-bundled minified dist for official Contentful SDK; not obfuscation. ai
source-diff net-exec-file:dist/index-DamoDgBk.js AI (source-diff): Bundled SDK build output; same benign encoder logic. ai
source-diff net-exec-file:dist/index-B_KvkeRr.cjs AI (source-diff): Bundled SDK build output; unicode-encoding logic, no dropper behavior. ai
source-diff obfuscated-file:dist/index-Bkc6mCY-.cjs AI (source-diff): Vite-bundled dist; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/index-Bkc6mCY-.cjs AI (source-diff): Bundled SDK build; encoding/URL logic, no malicious fetch-exec. ai
source-diff net-exec-file:dist/index-DJiGEKYp.js AI (source-diff): Bundled SDK build; encoding/URL logic, no malicious fetch-exec. ai
source-diff obfuscated-file:dist/index-jnO_t1cS.cjs AI (source-diff): Vite-minified dist of the invisible-unicode encoder; benign build output. ai
source-diff net-exec-file:dist/index-BtEraJDq.js AI (source-diff): Minified SDK bundle, no dropper behavior; stable build artifact. ai
source-diff net-exec-file:dist/index-jnO_t1cS.cjs AI (source-diff): Minified SDK bundle, no dropper behavior; stable build artifact. ai
source-diff obfuscated-file:dist/index-DHSZd87r.cjs AI (source-diff): Vite build output of Contentful content-source-maps codec; long lines are minified, not obfuscated. ai
source-diff net-exec-file:dist/index-DHSZd87r.cjs AI (source-diff): Encoder/JSON.parse logic misfires net-exec heuristic; benign SDK code. ai
source-diff net-exec-file:dist/index-BIOiMqgB.js AI (source-diff): Same SDK bundle, ESM variant; benign. ai
source-diff obfuscated-file:dist/index-PRKMEC9g.cjs AI (source-diff): Vite-bundled dist output; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/index-CQPxCeNq.js AI (source-diff): Same bundled SDK source-map encoding; benign build artifact. ai
source-diff net-exec-file:dist/index-PRKMEC9g.cjs AI (source-diff): Bundled SDK; encoding/URL-parse logic, no fetched-binary execution. ai
source-diff obfuscated-file:dist/index-CJoIxScS.cjs AI (source-diff): Zero-width Unicode edit-info encoder from content-source-maps, not obfuscation; bundled dist output. ai
source-diff net-exec-file:dist/index-ff-Ac6Z7.js AI (source-diff): Same bundled SDK code as .cjs; benign for this package. ai
source-diff net-exec-file:dist/index-CJoIxScS.cjs AI (source-diff): Bundled SDK dist; net+parse are the live-preview fetch/encode paths, no fetched-binary exec. ai
source-diff net-exec-file:dist/index-DOW5gga0.js AI (source-diff): Bundled first-party SDK; same encoder logic, no exfil target. ai
source-diff obfuscated-file:dist/index-21SNnixq.cjs AI (source-diff): Minified build output; zero-width-codepoint edit-info encoder is core SDK function. ai
source-diff net-exec-file:dist/index-21SNnixq.cjs AI (source-diff): Net+exec heuristic on bundled first-party SDK; no hostile destination in sample. ai
source-diff net-exec-file:dist/index-Dhg_FUK6.cjs AI (source-diff): Encoder/URL parsing in Vite bundle, no fetched-binary exec; false positive for this package. ai
source-diff net-exec-file:dist/index-D-TlChK0.js AI (source-diff): Same encoder logic in ESM dist bundle; benign build output. ai
source-diff obfuscated-file:dist/index-Dhg_FUK6.cjs AI (source-diff): Invisible-Unicode source-maps encoder in bundled dist; benign build output for this SDK. ai
source-diff obfuscated-file:dist/index-DuGfCK7B.cjs AI (source-diff): Vite-bundled dist; invisible-char source-map encoding, not obfuscation. ai
source-diff net-exec-file:dist/index-CcU-PVh0.js AI (source-diff): Bundled build output of legit SDK; no hostile fetch+exec. ai
source-diff net-exec-file:dist/index-DuGfCK7B.cjs AI (source-diff): Bundled build output of legit SDK; no hostile fetch+exec. ai
source-diff net-exec-file:dist/index-DVicdrJv.cjs AI (source-diff): Bundled build; URL/dynamic patterns are the SDK's benign source-map logic. ai
source-diff obfuscated-file:dist/index-DVicdrJv.cjs AI (source-diff): Minified vite build output; unicode encoding is the source-maps feature, not obfuscation. ai
source-diff net-exec-file:dist/index-CzUiJVZs.js AI (source-diff): Same bundled SDK output, no hostile destination. ai
source-diff obfuscated-file:dist/index-2lsIzeme.cjs AI (source-diff): Vite-bundled dist output; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/index-D8MrX8ez.js AI (source-diff): Bundled SDK build output; benign URL parsing + JSON encoding. ai
source-diff net-exec-file:dist/index-2lsIzeme.cjs AI (source-diff): Bundled SDK; URL/encode logic, no fetched-code execution. ai
source-diff obfuscated-file:dist/index-o4M5dVAP.cjs AI (source-diff): Vite-bundled minified output; invisible-Unicode encoding is the SDK's content-source-maps feature. ai
source-diff net-exec-file:dist/index-o4M5dVAP.cjs AI (source-diff): Bundled SDK output; URL/regex parsing not dropper behavior, no fetched-binary exec. ai
source-diff net-exec-file:dist/index-D2R9i9P7.js AI (source-diff): Same bundled SDK output as CJS twin; benign for this package. ai
source-diff net-exec-file:dist/index-CHsPjn18.js AI (source-diff): Same minified SDK bundle as .cjs; benign build output. ai
source-diff obfuscated-file:dist/index-BiHDZgVT.cjs AI (source-diff): Vite-minified dist build output, not obfuscation; regenerated each release. ai
source-diff net-exec-file:dist/index-BiHDZgVT.cjs AI (source-diff): Minified SDK bundle; zero-width-char encoder tables, no malicious network+exec behavior. ai
source-diff net-exec-file:dist/index-DzZfHxgU.cjs AI (source-diff): Bundled SDK; net+exec patterns are normal live-preview build output. ai
source-diff net-exec-file:dist/index-BBVabXHn.js AI (source-diff): Bundled SDK; net+exec patterns are normal live-preview build output. ai
source-diff obfuscated-file:dist/index-DzZfHxgU.cjs AI (source-diff): Vite-bundled dist; long lines are minified codec, not obfuscation. ai
source-diff net-exec-file:dist/index-DqNFIc9P.js AI (source-diff): Bundled SDK code; benign encoding logic, not remote code execution. ai
source-diff net-exec-file:dist/index-CPOjLBZc.cjs AI (source-diff): Bundled SDK code; URL/JSON parsing not fetch+eval dropper. ai
source-diff obfuscated-file:dist/index-CPOjLBZc.cjs AI (source-diff): Minified vite build output; content-source-map char encoding, no obfuscation payload. ai
source-diff net-exec-file:dist/index--w29-VoG.js AI (source-diff): Same bundled SDK output; benign network+eval false positive. ai
source-diff obfuscated-file:dist/index-CaRNoz-h.cjs AI (source-diff): Vite-bundled minified dist output; per-build hashed filenames recur every release. ai
source-diff net-exec-file:dist/index-CaRNoz-h.cjs AI (source-diff): SDK live-update fetch + minified bundle; benign for this package. ai
source-diff obfuscated-file:dist/index-CYPwm4cp.cjs AI (source-diff): Vite-bundled dist output of official Contentful SDK; minified, not obfuscated. ai
source-diff net-exec-file:dist/index-CYPwm4cp.cjs AI (source-diff): Bundled SDK build; net+exec heuristic on minified vendor code, no hostile target. ai
source-diff net-exec-file:dist/index-Cu3MQRv6.js AI (source-diff): Same bundled SDK output, ESM variant; benign build artifact. ai
source-diff obfuscated-file:dist/index-BXGAUPnI.cjs AI (source-diff): Vite build output; unicode encoding is the SDK's documented content-source-maps feature. ai
source-diff net-exec-file:dist/index-BXGAUPnI.cjs AI (source-diff): Bundled SDK dist; no hostile fetch/exec target, benign preview-SDK code. ai
source-diff net-exec-file:dist/index-C5OFgc49.js AI (source-diff): Bundled SDK dist; no hostile fetch/exec target, benign preview-SDK code. ai
source-diff obfuscated-file:dist/index-BTGK0QIv.cjs AI (source-diff): Vite-minified dist; long lines are build output, not obfuscation. ai
source-diff net-exec-file:dist/index-BTGK0QIv.cjs AI (source-diff): Minified SDK bundle; codepoint encoding is content-source-maps feature, no hostile net target. ai
source-diff net-exec-file:dist/index-B7CZzeKh.js AI (source-diff): Same minified SDK bundle; benign source-maps encoding logic. ai
source-diff obfuscated-file:dist/index-CihlSKQp.cjs AI (source-diff): Vite-minified dist output of official Contentful SDK; long lines are build artifact. ai
source-diff net-exec-file:dist/index-DVEO208b.js AI (source-diff): Minified bundle; encoding tables are content-source-maps, no hostile network/exec target. ai
source-diff net-exec-file:dist/index-CihlSKQp.cjs AI (source-diff): Minified bundle; encoding tables are content-source-maps, no hostile network/exec target. ai
source-diff net-exec-file:dist/index-1VdKaGiK.js AI (source-diff): Same bundled SDK logic in ESM form; benign. ai
source-diff obfuscated-file:dist/index-h-4JlUBz.cjs AI (source-diff): Vite-minified build output of content-source-maps encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-h-4JlUBz.cjs AI (source-diff): Bundled SDK code; URL/JSON.parse are encoding helpers, no dropper behavior. ai
source-diff obfuscated-file:dist/index-CiphPJIY.cjs AI (source-diff): Minified vite bundle of the source-maps encoder, not obfuscation; stable build output. ai
source-diff net-exec-file:dist/index-CiphPJIY.cjs AI (source-diff): Bundled SDK encoding logic; no hostile fetch/exec target. ai
source-diff net-exec-file:dist/index-r54_vu7f.js AI (source-diff): Same bundled SDK output, ESM variant; benign. ai
source-diff net-exec-file:dist/index-UxfOQw7J.js AI (source-diff): Same bundled SDK code; benign encode/decode logic. ai
source-diff net-exec-file:dist/index-DBF-Q4u3.cjs AI (source-diff): Build output; URL/JSON handling triggers heuristic, no fetched-code execution. ai
source-diff obfuscated-file:dist/index-DBF-Q4u3.cjs AI (source-diff): Vite-bundled minified output of the SDK's unicode source-map encoder; not obfuscation. ai
source-diff net-exec-file:dist/index-VfQMCowF.js AI (source-diff): Bundled ESM SDK output; benign live-preview networking. ai
source-diff net-exec-file:dist/index-Co7Fd_cL.cjs AI (source-diff): Bundled SDK output; net+exec pattern-match on build bundle, no hostile target. ai
source-diff obfuscated-file:dist/index-Co7Fd_cL.cjs AI (source-diff): Minified vite output implementing zero-width content-source-map encoding; not obfuscation. ai
source-diff net-exec-file:dist/index-CItojYns.js AI (source-diff): Bundled SDK output; benign build artifact from official publisher. ai
source-diff obfuscated-file:dist/index-Dt2KLugV.cjs AI (source-diff): Zero-width-codepoint edit-info encoder, core live-preview feature; minified dist, not obfuscation. ai
source-diff net-exec-file:dist/index-Dt2KLugV.cjs AI (source-diff): Bundled SDK output; no hostile fetch/exec destination in a first-party Contentful package. ai
source-diff net-exec-file:dist/index-DT8Q_2SQ.js AI (source-diff): Same first-party SDK bundle; no dropper behavior. ai
source-diff obfuscated-file:dist/index-B2kLB0KB.cjs AI (source-diff): Minified bundle of Contentful zero-width edit-info encoder; long lines are build output. ai
source-diff net-exec-file:dist/index-B2kLB0KB.cjs AI (source-diff): Heuristic misfire on encode/decode logic; no fetched-payload execution. ai
source-diff net-exec-file:dist/index-DuyuNEnF.js AI (source-diff): Same bundled SDK output; network+parse, not code drop. ai
source-diff net-exec-file:dist/index-BKCe-T5V.cjs AI (source-diff): Bundled SDK fetch + JSON decode; no fetched-binary execution. Benign for this package. ai
source-diff obfuscated-file:dist/index-BKCe-T5V.cjs AI (source-diff): Minified bundle output of live-preview SDK; unicode encoding is documented inspector feature, not obfuscation. ai
source-diff obfuscated-file:dist/index-BmcbBbOf.cjs AI (source-diff): Bundled zero-width-char encoding for inspector edit-info; not obfuscation, stable for this SDK. ai
source-diff net-exec-file:dist/index-CM-lZf9g.js AI (source-diff): Same benign bundled SDK code, ESM variant. ai
source-diff net-exec-file:dist/index-BmcbBbOf.cjs AI (source-diff): SDK build output; net+JSON.parse pattern, no fetched-binary exec. ai
source-diff net-exec-file:dist/index-Bg-XidIL.cjs AI (source-diff): URL parsing + JSON codec, no fetched-code execution; legit SDK build output. ai
source-diff net-exec-file:dist/index-C1RgK1xT.js AI (source-diff): Same benign edit-info codec in ESM dist; no dropper behavior. ai
source-diff obfuscated-file:dist/index-Bg-XidIL.cjs AI (source-diff): Contentful invisible-char edit-encoding in bundled dist; not obfuscation. ai
source-diff net-exec-file:dist/index-CNgtbTCn.cjs AI (source-diff): SDK bundle; codepoint tables trip net/exec heuristic, no real dropper behavior. ai
source-diff net-exec-file:dist/index-Bu4KD0rP.js AI (source-diff): Same benign SDK bundle output as the cjs variant. ai
source-diff obfuscated-file:dist/index-CNgtbTCn.cjs AI (source-diff): Minified bundle of Contentful zero-width encoding logic, not obfuscation. ai
source-diff net-exec-file:dist/index-BgQyFZeN.cjs AI (source-diff): Bundled build; unicode-encoding for source maps, no hostile net/exec target. ai
source-diff net-exec-file:dist/index-mpy6K7D9.js AI (source-diff): Same bundled build output, benign SDK logic. ai
source-diff obfuscated-file:dist/index-BgQyFZeN.cjs AI (source-diff): Minified vite build output; readable JS logic, not obfuscated. ai
source-diff obfuscated-file:dist/index-BO1Y-a0e.cjs AI (source-diff): Vite build output, not obfuscation; official Contentful SDK dist. ai
source-diff net-exec-file:dist/index-2NJWBdxg.js AI (source-diff): Minified bundle of SDK preview logic; no hostile net/exec target. ai
source-diff net-exec-file:dist/index-BO1Y-a0e.cjs AI (source-diff): Minified bundle of SDK preview logic; no hostile net/exec target. ai
source-diff net-exec-file:dist/index-O4mo4Att.js AI (source-diff): Same minified SDK bundle; benign network+decode for live preview. ai
source-diff net-exec-file:dist/index-DUOHoIJ7.cjs AI (source-diff): Minified SDK bundle; no hostile fetched destination, content-source-maps encoding logic. ai
source-diff obfuscated-file:dist/index-DUOHoIJ7.cjs AI (source-diff): Vite-minified dist output; long lines are build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/index-Doe9SN_6.cjs AI (source-diff): Bundled content-source-maps invisible-char encoder, not obfuscated payload; minified build output. ai
source-diff net-exec-file:dist/index-CyUSsFZT.js AI (source-diff): Same encoding logic in ESM variant; build output, not malware. ai
source-diff net-exec-file:dist/index-Doe9SN_6.cjs AI (source-diff): Codepoint encode/decode + JSON.parse, no fetched-binary exec; benign SDK feature. ai
source-diff obfuscated-file:dist/index-CpgJ20sf.cjs AI (source-diff): Minified Vite output of content-source-maps unicode encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-CpgJ20sf.cjs AI (source-diff): Codepoint encode/decode logic, no fetched-binary exec; bundled SDK dist. ai
source-diff net-exec-file:dist/index-C_TBFqeP.js AI (source-diff): Same bundled SDK dist; benign source-map encoding. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publish for official Contentful package. ai
source-diff net-exec-file:dist/index-DOTA3foM.js AI (source-diff): Bundled SDK build output; benign content-source-maps codec. ai
source-diff net-exec-file:dist/index-BQlezUIC.cjs AI (source-diff): Bundled SDK build output; no hostile fetch/exec target present. ai
source-diff obfuscated-file:dist/index-BQlezUIC.cjs AI (source-diff): Vite-bundled dist implementing content-source-maps unicode encoding; minified not obfuscated. ai
source-diff obfuscated-file:dist/index-gLc9iu1D.cjs AI (source-diff): Vite-bundled minified dist output, not obfuscation. ai
source-diff net-exec-file:dist/index-76hH1uuh.js AI (source-diff): Minified build output; benign encoding logic. ai
source-diff net-exec-file:dist/index-gLc9iu1D.cjs AI (source-diff): Minified build output; content-source-maps encoding logic, no hostile destination. ai
source-diff obfuscated-file:dist/index-DBoLcxQt.cjs AI (source-diff): Vite-bundled dist; long lines are minification plus SDK's unicode edit-tag encoding, not obfuscation. ai
source-diff net-exec-file:dist/index-DBoLcxQt.cjs AI (source-diff): Minified SDK bundle; no hostile fetch/exec destination in a well-known Contentful package. ai
source-diff net-exec-file:dist/index-BI1JEOp6.js AI (source-diff): Minified SDK bundle; benign network/exec patterns in official package. ai
source-diff net-exec-file:dist/index-BQECtOLI.js AI (source-diff): Same minified bundle; benign preview SDK build output. ai
source-diff obfuscated-file:dist/index-Dvpc8HAP.cjs AI (source-diff): Vite-minified build output of content-source-maps encoder, not obfuscation. ai
source-diff net-exec-file:dist/index-Dvpc8HAP.cjs AI (source-diff): Heuristic misfire on minified bundle; no dropper behavior in this SDK. ai
source-diff net-exec-file:dist/index-h9k30EFp.js AI (source-diff): Minified bundle of Contentful SDK; no dropper behavior. ai
source-diff net-exec-file:dist/index-CXg9wjEU.cjs AI (source-diff): Minified bundle of Contentful SDK; no dropper behavior. ai
source-diff obfuscated-file:dist/index-CXg9wjEU.cjs AI (source-diff): vite build output; unicode-encoding for content-source-maps, not obfuscated malware. ai
source-diff obfuscated-file:dist/index-SKEPZj9o.cjs AI (source-diff): Minified vite build output of documented content-source-map encoding; stable for this package. ai
source-diff net-exec-file:dist/src-BV4mhU9H.js AI (source-diff): ESM bundle counterpart; same rolldown output, no malicious payload. ai
source-diff net-exec-file:dist/src-7Oe7qYiM.cjs AI (source-diff): Bundle includes live-preview SDK networking; no malicious payload. ai
source-diff obfuscated-file:dist/src-7Oe7qYiM.cjs AI (source-diff): Rolldown CJS bundle output; minification is expected for this package. ai
source-diff net-exec-file:dist/src-BVzLNsbv.cjs AI (source-diff): Bundled SDK with fetch calls and dynamic requires; expected for a live-preview SDK. ai
source-diff net-exec-file:dist/src-Dd1bV8rx.js AI (source-diff): ESM counterpart of the CJS bundle; same legitimate SDK code. ai
source-diff obfuscated-file:dist/src-BVzLNsbv.cjs AI (source-diff): Minified CJS bundle from rolldown; standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/src-CwJyHRfo.cjs AI (source-diff): CJS bundle minified by rolldown; standard build output for this package. ai
source-diff net-exec-file:dist/src-CTjB7PIV.js AI (source-diff): ESM bundle counterpart; same rolldown output with network + dynamic patterns from SDK logic. ai
source-diff net-exec-file:dist/src-CwJyHRfo.cjs AI (source-diff): Bundled SDK with network calls (fetch for CMS) and dynamic require shims; not malicious. ai
source-diff net-exec-file:dist/src-DmYUaDf4.js AI (source-diff): ESM bundle counterpart; same benign bundled code as CJS variant. ai
source-diff net-exec-file:dist/src-BAzzj2P1.cjs AI (source-diff): Bundled CJS output; network+exec pattern is from bundled dependencies, not malware. ai
source-diff obfuscated-file:dist/src-BAzzj2P1.cjs AI (source-diff): Minified CJS bundle from rolldown; stega encoding is part of live-preview tagging feature. ai
source-diff obfuscated-file:dist/src-gyVL5-Kj.cjs AI (source-diff): Minified rolldown bundle output; standard for this package's build pipeline. ai
source-diff net-exec-file:dist/src-w-hF_slJ.js AI (source-diff): ESM bundle counterpart; same legitimate live-preview network calls. ai
source-diff net-exec-file:dist/src-gyVL5-Kj.cjs AI (source-diff): Bundle contains fetch/WebSocket for live preview SDK functionality, not malware. ai
phantom-deps phantom-dep:flatted AI (phantom-deps): Monorepo SDK; declared deps used transitively or in config, not a real phantom risk. ai
phantom-deps phantom-dep:@contentful/rich-text-types AI (phantom-deps): Same-org peer dep; stable false positive for this package. ai
phantom-deps phantom-dep:lodash.isequal AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. ai
phantom-deps phantom-dep:graphql-tag AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. ai
phantom-deps phantom-dep:json-pointer AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. ai

Versions (showing 51 of 124)

View all versions
Version Deps Published
4.10.12 6 / 14
4.10.11 6 / 14
4.10.10 6 / 14
4.10.9 6 / 14
4.10.8 6 / 14
4.10.7 6 / 14
4.10.6 6 / 14
4.10.5 6 / 14
4.10.4 6 / 14
4.10.3 6 / 14
4.10.2 6 / 14
4.10.1 6 / 14
4.10.0 6 / 14
4.9.13 6 / 14
4.9.12 6 / 14
4.9.11 6 / 14
4.9.10 6 / 14
4.9.9 6 / 14
4.9.8 6 / 14
4.9.7 6 / 14
4.9.6 6 / 14
4.9.5 6 / 14
4.9.4 6 / 14
4.9.3 6 / 14
4.9.2 6 / 14
4.9.1 6 / 14
4.9.0 6 / 14
4.8.4 6 / 14
4.8.3 6 / 14
4.8.2 6 / 14
4.7.0 6 / 14
4.6.58 6 / 14
4.6.57 6 / 14
4.6.56 6 / 14
4.6.55 6 / 14
4.6.54 6 / 14
4.6.53 6 / 14
4.6.52 6 / 14
4.6.51 6 / 14
4.6.50 6 / 14
4.6.49 6 / 14
4.6.48 6 / 14
4.6.47 6 / 14
4.6.46 6 / 14
4.6.45 6 / 14
4.6.44 6 / 14
4.6.43 6 / 14
4.6.42 6 / 14
4.6.41 6 / 14
4.6.40 6 / 14
4.6.39 6 / 14

v4.10.12

4 findings
HIGH New obfuscated file: dist/src-VbuEYWL_.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src-VbuEYWL_.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src-e13kLMf5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.11

4 findings
HIGH New obfuscated file: dist/src-CazfDf20.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src-CazfDf20.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src-gOMxjmYt.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.10

4 findings
HIGH New obfuscated file: dist/src-D9U4PMO2.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src-D9U4PMO2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src-DxKlL-rp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.9

4 findings
HIGH New obfuscated file: dist/src-C7cXhlOc.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src-C7cXhlOc.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src-DpXJbZnK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.11

4 findings
HIGH New obfuscated file: dist/index-uwm6IWYN.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-uwm6IWYN.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-C17nSolv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.10

4 findings
HIGH New obfuscated file: dist/index-l7NjQcXz.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-l7NjQcXz.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-D7yy0vxo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.9

4 findings
HIGH New obfuscated file: dist/index-BnLyXVi4.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BnLyXVi4.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-DGlupfJI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.7

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-03-02) provenance

This version was published by a different npm account than previous versions on 2026-03-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-BYZWrixv.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BYZWrixv.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-Bw-_OeWY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.6

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-02-23) provenance

This version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-Dhg_FUK6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Dhg_FUK6.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-D-TlChK0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.5

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-02-19) provenance

This version was published by a different npm account than previous versions on 2026-02-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DHSZd87r.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DHSZd87r.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-BIOiMqgB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.4

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-02-16) provenance

This version was published by a different npm account than previous versions on 2026-02-16. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-y_tTfYG2.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-y_tTfYG2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-C5Din3Pu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.3

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-02-09) provenance

This version was published by a different npm account than previous versions on 2026-02-09. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-Doe9SN_6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Doe9SN_6.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-CyUSsFZT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.2

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-02-02) provenance

This version was published by a different npm account than previous versions on 2026-02-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DjhlJY6b.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DjhlJY6b.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-BWioMUj8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.1

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2026-01-26) provenance

This version was published by a different npm account than previous versions on 2026-01-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DPa35cVv.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DPa35cVv.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-DIczhOoz.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.0

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-12-17) provenance

This version was published by a different npm account than previous versions on 2025-12-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-DJTHLeG4.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DJTHLeG4.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-JyAyuKLS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.4

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-12-15) provenance

This version was published by a different npm account than previous versions on 2025-12-15. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-CpgJ20sf.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CpgJ20sf.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-C_TBFqeP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.3

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-12-08) provenance

This version was published by a different npm account than previous versions on 2025-12-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-Cc8lUfSx.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Cc8lUfSx.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-CWfya0MQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.2

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-12-05) provenance

This version was published by a different npm account than previous versions on 2025-12-05. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-VAB_rHFi.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-VAB_rHFi.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-incI5N0z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.0

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-11-24) provenance

This version was published by a different npm account than previous versions on 2025-11-24. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-55xaTOC0.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-55xaTOC0.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-BiG5czIX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.58

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-11-24) provenance

This version was published by a different npm account than previous versions on 2025-11-24. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-ByITfjmi.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ByITfjmi.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-Bb-hmh7b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.57

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-11-17) provenance

This version was published by a different npm account than previous versions on 2025-11-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-BdQ-t5j7.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BdQ-t5j7.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-DVTW8xJk.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.56

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-11-10) provenance

This version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-CzzyreLd.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CzzyreLd.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-D-6iR_jP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.55

5 findings
HIGH Publisher changed: contentful-ecosystem → GitHub Actions (on 2025-11-10) provenance

This version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index-CJoIxScS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CJoIxScS.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-ff-Ac6Z7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.54

4 findings
HIGH New obfuscated file: dist/index-CAESNJuv.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CAESNJuv.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/index-CChN__FL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.