← Home

@ecan-bi/pivot-table

### 项目开发指南 ``` // 下载项目依赖(node_modules) yarn install --registry=https://registry.npm.taobao.org

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

huangjunhaozhanxiaohua

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/index-a109dbd3.mjs AI (source-diff): axios import in bundled UI library code, no exfil target observed. ai
source-diff obfuscated-file:dist/index-a109dbd3.mjs AI (source-diff): Vite/Rollup bundle output (banner + vue/echarts imports), not true obfuscation. ai
source-diff obfuscated-file:dist/index-a1cc897c.mjs AI (source-diff): Vite/Rollup bundle output for a Vue component library, not true obfuscation. ai
source-diff net-exec-file:dist/index-a1cc897c.mjs AI (source-diff): Bundled axios/echarts library code, no dropper behavior observed. ai
source-diff net-exec-file:dist/index-50bba2e6.mjs AI (source-diff): Bundled UI library code (axios/echarts/ant-design-vue), no evidence of dropper behavior. ai
source-diff obfuscated-file:dist/index-50bba2e6.mjs AI (source-diff): Vite/Rollup bundle output with accompanying sourcemap; not true obfuscation. ai
source-diff net-exec-file:dist/index-02780d26.mjs AI (source-diff): axios usage in bundled UI component, no hostile destination. ai
source-diff obfuscated-file:dist/index-02780d26.mjs AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/index-6395f4f4.mjs AI (source-diff): Bundled UI library using axios/vue normally; no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/index-6395f4f4.mjs AI (source-diff): Vite/Rollup bundle output, not true obfuscation; no malicious behavior found. ai
source-diff net-exec-file:dist/index-3ca16065.mjs AI (source-diff): axios import is the component's own HTTP client bundled inline, not a dropper. ai
source-diff obfuscated-file:dist/index-3ca16065.mjs AI (source-diff): Bundled vite/esbuild output, not true obfuscation; standard vue-component bundle. ai
source-diff net-exec-file:dist/index-35087210.mjs AI (source-diff): Bundled UI lib importing axios/echarts; no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/index-35087210.mjs AI (source-diff): Vite/rollup bundled output with source-map, not true obfuscation. ai
source-diff obfuscated-file:dist/index-d3de25f9.mjs AI (source-diff): Vite/rollup-bundled ESM dist with banner header; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/index-d3de25f9.mjs AI (source-diff): axios + Vue dynamic component resolution in bundled output; no fetched binary or hostile target. ai
source-diff obfuscated-file:dist/index-7e6d3d53.mjs AI (source-diff): Standard vite bundle output with recognizable imports; minified not obfuscated. ai
source-diff net-exec-file:dist/index-7e6d3d53.mjs AI (source-diff): axios+dynamic code inside a UI bundle, no evidence of dropper behavior. ai
source-diff obfuscated-file:dist/index-7863b01b.mjs AI (source-diff): Standard Vite/Rollup minified bundle, not obfuscation. ai
source-diff net-exec-file:dist/index-7863b01b.mjs AI (source-diff): Bundled axios/vue lib triggers heuristic; no malicious network+exec behavior found. ai
source-diff net-exec-file:dist/index-1eaea0ed.mjs AI (source-diff): axios import + normal JS eval-like patterns in bundled UI lib, no dropper behavior found. ai
source-diff obfuscated-file:dist/index-1eaea0ed.mjs AI (source-diff): Minified vite bundle with standard Vue/axios imports, not true obfuscation. ai
source-diff net-exec-file:dist/index-0859ac36.mjs AI (source-diff): axios + dynamic code patterns are normal in a bundled Vue component lib, no malicious target found. ai
source-diff obfuscated-file:dist/index-0859ac36.mjs AI (source-diff): Bundled Vite/Rollup ESM output for a Vue UI library, not true obfuscation. ai
source-diff net-exec-file:dist/index-8b504455.mjs AI (source-diff): axios import triggers network heuristic; no dropper behavior in code. ai
source-diff obfuscated-file:dist/index-8b504455.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/index-1e9eac99.mjs AI (source-diff): axios import in bundled UI lib, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/index-1e9eac99.mjs AI (source-diff): Vite/Rollup bundle output, not obfuscation. ai
source-diff net-exec-file:dist/index-0c084163.mjs AI (source-diff): axios+eval patterns are bundled framework code, no dropper behavior. ai
source-diff obfuscated-file:dist/index-0c084163.mjs AI (source-diff): Standard Vite/Rollup bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-0a929c31.mjs AI (source-diff): Vite/Rollup bundle output, not true obfuscation; matches package's normal build artifacts. ai
source-diff net-exec-file:dist/index-0a929c31.mjs AI (source-diff): axios/echarts usage inside bundled UI component library, no hostile destination. ai
source-diff net-exec-file:dist/index-1c8a46a1.mjs AI (source-diff): Standard axios/vue bundle; network+exec pattern is normal for a UI lib bundle. ai
source-diff obfuscated-file:dist/index-1c8a46a1.mjs AI (source-diff): Bundled Vue component library output, not true obfuscation. ai
source-diff net-exec-file:dist/index-810def50.mjs AI (source-diff): Standard axios import inside bundled UI code, no dropper behavior. ai
source-diff obfuscated-file:dist/index-810def50.mjs AI (source-diff): Bundled Vue component library output, not true obfuscation. ai
source-diff net-exec-file:dist/index-c36e79f0.mjs AI (source-diff): axios/echarts bundled into build output; no exfil destination identified. ai
source-diff obfuscated-file:dist/index-c36e79f0.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; matches package's UI-library purpose. ai
source-diff obfuscated-file:dist/index-b5c42d49.mjs AI (source-diff): Vite/rollup bundle output with banner comment and standard imports; not true obfuscation. ai
source-diff net-exec-file:dist/index-b5c42d49.mjs AI (source-diff): axios/echarts usage inside bundled UI library, no exfil behavior to unrelated destination. ai
source-diff obfuscated-file:dist/index-2d589426.mjs AI (source-diff): Bundled minified Vue component output, not true obfuscation. ai
source-diff net-exec-file:dist/index-2d589426.mjs AI (source-diff): axios/dynamic-import inside UI bundle, no exfil destination shown. ai
source-diff net-exec-file:dist/index-635d9326.mjs AI (source-diff): Bundle uses axios/echarts normally; no exfil or dropper behavior found. ai
source-diff obfuscated-file:dist/index-635d9326.mjs AI (source-diff): Standard bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/index-41d959ec.mjs AI (source-diff): Bundled axios/echarts imports, no malicious exec pattern found. ai
source-diff obfuscated-file:dist/index-41d959ec.mjs AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/index-03c764ca.mjs AI (source-diff): Same bundled file; axios import is a normal dependency, no exfil target found. ai
source-diff obfuscated-file:dist/index-03c764ca.mjs AI (source-diff): Vite/Rollup bundle output with banner comment and standard vue/echarts imports, not obfuscation. ai
source-diff net-exec-file:dist/index-fd1a691d.mjs AI (source-diff): axios import in bundled UI lib, no exfil or fetched-binary behavior. ai
source-diff obfuscated-file:dist/index-fd1a691d.mjs AI (source-diff): Bundled Vue component code, not true obfuscation (readable imports, no _0x/eval-atob). ai
source-diff net-exec-file:dist/index-d073710e.mjs AI (source-diff): axios import in bundled UI library, not a dropper/loader pattern. ai
source-diff obfuscated-file:dist/index-d073710e.mjs AI (source-diff): Bundled Vite/Rollup output with long lines; not true obfuscation. ai
source-diff obfuscated-file:dist/index-94659242.mjs AI (source-diff): Standard Vite bundle output, not true obfuscation (_0x/eval-atob). ai
source-diff net-exec-file:dist/index-94659242.mjs AI (source-diff): Bundled axios usage inside build output, not a dropper pattern. ai
source-diff obfuscated-file:dist/index-e10ad265.mjs AI (source-diff): Vite/rollup bundle output, not true obfuscation (_0x/eval-atob/packer). ai
source-diff net-exec-file:dist/index-e10ad265.mjs AI (source-diff): Bundled UI library code; network+exec pattern is axios/vue framework code, not dropper behavior. ai
source-diff net-exec-file:dist/index-64a64e77.mjs AI (source-diff): Bundled build artifact importing axios/vue; no fetched-binary or exfil behavior. ai
source-diff obfuscated-file:dist/index-64a64e77.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-0614a2e5.mjs AI (source-diff): Vite/Rollup bundle output with long minified lines, not true obfuscation. ai
source-diff net-exec-file:dist/index-0614a2e5.mjs AI (source-diff): Bundled axios+vue app code, no fetched-binary or exfil behavior found. ai
source-diff obfuscated-file:dist/index-4a10f9f9.mjs AI (source-diff): Bundled Vite/rollup output, not true obfuscation (no _0x/eval-atob/packer). ai
source-diff net-exec-file:dist/index-4a10f9f9.mjs AI (source-diff): axios import is bundled dep used for the library's own data fetching, not exfil. ai
source-diff net-exec-file:dist/index-a1bf09b5.mjs AI (source-diff): axios import in bundled UI library code, no dropper/loader behavior found. ai
source-diff encoded-string-file:dist/index.umd.js AI (source-diff): Long strings are CSS/template literals in minified UMD bundle. ai
source-diff obfuscated-file:dist/index-a1bf09b5.mjs AI (source-diff): Bundled Vite/Rollup output with recognizable imports, not true obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org scoped dependency, not a supply-chain substitution. ai
source-diff net-exec-file:dist/index-f06fe9ac.mjs AI (source-diff): Bundled UI lib code (axios+echarts imports), not a dropper. ai
source-diff obfuscated-file:dist/index-f06fe9ac.mjs AI (source-diff): Minified Vite/Rollup bundle output, not true obfuscation. ai
provenance no-provenance AI (provenance): Org-scoped internal BI component; lack of provenance is consistent across all versions and not a risk indicator here. ai
phantom-deps phantom-dep:@ecan-bi/datav AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this package's build pattern. ai
phantom-deps phantom-dep:monaco-editor AI (phantom-deps): Listed in both dependencies and devDependencies; config-file reference is a stable false positive. ai
phantom-deps phantom-dep:@visactor/vtable-export AI (phantom-deps): Referenced in config files only; consistent with bundled/peer usage pattern across versions. ai
phantom-deps phantom-dep:@visactor/vtable AI (phantom-deps): Referenced in config files only; consistent with bundled/peer usage pattern across versions. ai

Versions (showing 51 of 57)

View all versions
Version Deps Published
1.1.16 5 / 31
1.1.15 5 / 31
1.1.14 5 / 31
1.1.12 5 / 31
1.1.11 5 / 31
1.1.10 5 / 31
1.1.8 5 / 31
1.1.7 5 / 31
1.1.6 5 / 31
1.1.5 5 / 31
1.1.4 5 / 31
1.1.3 5 / 31
1.1.2 5 / 31
1.1.1 5 / 31
1.0.79 5 / 31
1.0.78 5 / 31
1.0.77 5 / 31
1.0.76 5 / 31
1.0.75 5 / 31
1.0.74 4 / 31
1.0.73 4 / 31
1.0.72 4 / 31
1.0.71 3 / 31
1.0.70 3 / 31
1.0.68 3 / 31
1.0.67 3 / 31
1.0.66 3 / 31
1.0.65 3 / 31
1.0.64 3 / 31
1.0.63 3 / 31
1.0.62 3 / 31
1.0.61 3 / 31
1.0.60 3 / 31
1.0.59 3 / 31
1.0.58 3 / 31
1.0.56 3 / 31
1.0.55 3 / 31
1.0.54 3 / 31
1.0.53 3 / 31
1.0.52 3 / 31
1.0.51 3 / 31
1.0.50 3 / 31
1.0.49 3 / 31
1.0.48 3 / 31
1.0.47 3 / 31
1.0.46 3 / 31
1.0.45 3 / 31
1.0.44 3 / 31
1.0.43 3 / 31
1.0.42 3 / 31
1.0.41 3 / 31

v1.1.16

4 findings
HIGH New obfuscated file: dist/index-a1bf09b5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-a1bf09b5.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.15

4 findings
HIGH New obfuscated file: dist/index-a109dbd3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-a109dbd3.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.14

4 findings
HIGH New obfuscated file: dist/index-8b504455.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-8b504455.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

4 findings
HIGH New obfuscated file: dist/index-03c764ca.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-03c764ca.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

4 findings
HIGH New obfuscated file: dist/index-a1cc897c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-a1cc897c.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.79

4 findings
HIGH New obfuscated file: dist/index-64a64e77.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-64a64e77.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.78

4 findings
HIGH New obfuscated file: dist/index-0614a2e5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-0614a2e5.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.77

4 findings
HIGH New obfuscated file: dist/index-3ca16065.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-3ca16065.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.76

4 findings
HIGH New obfuscated file: dist/index-fd1a691d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-fd1a691d.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.75

4 findings
HIGH New obfuscated file: dist/index-810def50.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-810def50.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.74

3 findings
HIGH New obfuscated file: dist/index-b5c42d49.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-b5c42d49.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.73

3 findings
HIGH New obfuscated file: dist/index-c36e79f0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-c36e79f0.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.72

3 findings
HIGH New obfuscated file: dist/index-f06fe9ac.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-f06fe9ac.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.71

3 findings
HIGH New obfuscated file: dist/index-d073710e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-d073710e.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.70

3 findings
HIGH New obfuscated file: dist/index-635d9326.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-635d9326.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.68

3 findings
HIGH New obfuscated file: dist/index-635d9326.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-635d9326.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.67

3 findings
HIGH New obfuscated file: dist/index-0c084163.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-0c084163.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.66

3 findings
HIGH New obfuscated file: dist/index-2d589426.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-2d589426.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.65

3 findings
HIGH New obfuscated file: dist/index-0859ac36.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-0859ac36.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.64

3 findings
HIGH New obfuscated file: dist/index-1c8a46a1.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-1c8a46a1.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.63

3 findings
HIGH New obfuscated file: dist/index-4a10f9f9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-4a10f9f9.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.62

3 findings
HIGH New obfuscated file: dist/index-7e6d3d53.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-7e6d3d53.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.61

3 findings
HIGH New obfuscated file: dist/index-50bba2e6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-50bba2e6.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.60

3 findings
HIGH New obfuscated file: dist/index-1e9eac99.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-1e9eac99.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.59

3 findings
HIGH New obfuscated file: dist/index-41d959ec.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-41d959ec.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.58

3 findings
HIGH New obfuscated file: dist/index-02780d26.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-02780d26.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.56

3 findings
HIGH New obfuscated file: dist/index-7863b01b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-7863b01b.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.55

3 findings
HIGH New obfuscated file: dist/index-0a929c31.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-0a929c31.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.54

3 findings
HIGH New obfuscated file: dist/index-1eaea0ed.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-1eaea0ed.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.53

3 findings
HIGH New obfuscated file: dist/index-e10ad265.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-e10ad265.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.52

3 findings
HIGH New obfuscated file: dist/index-94659242.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-94659242.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.51

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.50

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.49

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.48

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.47

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.46

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.45

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.44

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.43

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.42

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.41

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.