← Home

@eforge-build/eforge

Autonomous plan-build-review CLI for code generation

32
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

schaakesolutions

Keywords

aiagentcode-generationclaude

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New dep is a same-org sibling at matching version (0.7.20); consistent with monorepo split, not a suspicious third-party dep. ai
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA provenance; consistent with legitimate automation adoption. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/actionscript-3-Cj-0sM4g.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ada-DhEA_nP5.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/andromeeda-CWmR-N6V.js AI (source-diff): Minified Shiki theme JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-ts-Kcd22Ido.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apache-D5R2GKIs.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apex-Qu8W4hal.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-html-BZJbgpOD.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff obfuscated-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/abap-BRbAAyvE.js AI (source-diff): Minified Shiki language grammar JSON asset; not obfuscated malware. ai
source-diff net-exec-file:node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js AI (source-diff): Minified Vite UI asset containing language grammar JSON; no actual network fetch or dynamic exec payload. ai
source-diff large-new-source-files AI (source-diff): Large file count is expected: bundled shiki syntax-highlighting assets for monitor UI. ai

Versions (showing 32 of 32)

Version Deps Published
0.7.21 10 / 3
0.7.20 10 / 3
0.7.12 9 / 3
0.7.11 9 / 3
0.7.10 9 / 3
0.7.9 9 / 3
0.7.8 9 / 3
0.7.7 9 / 3
0.7.6 9 / 3
0.7.4 9 / 3
0.7.3 9 / 3
0.7.2 9 / 3
0.7.1 9 / 3
0.7.0 9 / 3
0.6.2 9 / 3
0.6.0 9 / 3
0.5.12 9 / 3
0.5.11 9 / 3
0.5.10 9 / 3
0.5.9 9 / 3
0.5.8 9 / 3
0.5.6 9 / 3
0.5.5 9 / 3
0.5.4 9 / 3
0.5.3 9 / 3
0.5.2 9 / 3
0.5.1 9 / 3
0.5.0 9 / 3
0.4.3 9 / 3
0.4.2 9 / 3
0.4.1 9 / 3
0.4.0 9 / 3

v0.7.21

2 findings
HIGH Publisher changed: schaakesolutions → GitHub Actions (on 2026-05-20) provenance

This version was published by a different npm account than previous versions on 2026-05-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.20

2 findings
HIGH Publisher changed: schaakesolutions → GitHub Actions (on 2026-05-20) provenance

This version was published by a different npm account than previous versions on 2026-05-20. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.3

43 findings
HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/abap-BRbAAyvE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/actionscript-3-Cj-0sM4g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ada-DhEA_nP5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/andromeeda-CWmR-N6V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-html-BZJbgpOD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-ts-Kcd22Ido.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apache-D5R2GKIs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apex-Qu8W4hal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apl-OO-Vc-jI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/applescript-CBey3ErE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ara-CRKnUAN1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/asciidoc-1KYZEB6-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/asm-DAaViY0U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/astro-bCXlcRw_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/aurora-x-LPpmXm4i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/awk-ButuPTaW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-dark-Dv4ngVMP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-light-CxeOePuA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-mirage-i2YLXKmY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ballerina-DodmBVwR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bat-jA-YqDhG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/beancount-BCkjWTs-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bibtex-aOfmXHFj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bicep-BZLx0b6B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bird2-Bs7YDhA3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bsl-CPV9KqsG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/c-CRt7XGut.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/c3-BDcFIiRd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cadence-DaglWUgA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-frappe-CSAC76is.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-latte-Jt6sqtds.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-macchiato-HM96_05s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-mocha-CXgIAGBL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/clarity-DS5YLe8G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/clojure-BVGPdaE2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cmake-CCC7tP43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cobol-CSwIzl8C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/codeql-BGjlu3KC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/coffee-CiJtCEbh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/common-lisp-BE6wRQeA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

48 findings
HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/abap-BRbAAyvE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/actionscript-3-Cj-0sM4g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ada-DhEA_nP5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/andromeeda-CWmR-N6V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-html-BZJbgpOD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/angular-ts-Kcd22Ido.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apache-D5R2GKIs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apex-Qu8W4hal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/apl-OO-Vc-jI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/applescript-CBey3ErE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ara-CRKnUAN1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/asciidoc-1KYZEB6-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/asm-DAaViY0U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/astro-bCXlcRw_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/aurora-x-LPpmXm4i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/awk-ButuPTaW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-dark-Dv4ngVMP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-light-CxeOePuA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ayu-mirage-i2YLXKmY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/ballerina-DodmBVwR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bat-jA-YqDhG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/beancount-BCkjWTs-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bibtex-aOfmXHFj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bicep-BZLx0b6B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bird2-Bs7YDhA3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/blade-C4ts2lca.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/bsl-CPV9KqsG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/c-CRt7XGut.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/c3-BDcFIiRd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cadence-DaglWUgA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-frappe-CSAC76is.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-latte-Jt6sqtds.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-macchiato-HM96_05s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/catppuccin-mocha-CXgIAGBL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/clarity-DS5YLe8G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/clojure-BVGPdaE2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cmake-CCC7tP43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cobol-CSwIzl8C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/codeql-BGjlu3KC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/coffee-CiJtCEbh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/common-lisp-BE6wRQeA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/coq-CRT8yML1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/cpp-uiNWnWDw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/crystal-C07X5JcZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/csharp-Ca2kU4Te.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: node_modules/@eforge-build/monitor/dist/monitor-ui/assets/css-DJnfWLOW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.