@dynamic-labs-wallet/browser
3
Versions
Licensed under the Dynamic Labs, Inc. Terms Of Service (https://www.dynamic.xyz/terms-conditions)
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
packaging-at-dynamic-labs
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in wasm-bindgen generated glue code (libmpc_executor.js); expected pattern for WASM MPC crypto library. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Same wasm-bindgen generated file; new Function() is standard in WASM JS glue output. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode used for binary data handling in crypto/wallet SDK; no exfiltration context. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode used for EVM message formatting (keccak256 hashing); standard wallet SDK pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established org package under Dynamic Labs; missing metadata is a style choice, not a spam indicator. | ai | |
| phantom-deps | phantom-dep:@dynamic-labs-wallet/forward-mpc-client | AI (phantom-deps): Same org scope; likely re-exported or used indirectly through bundled output. | ai |
v0.0.68
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.67
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.66
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.