← Home

@eox/map

[Examples](https://eox-a.github.io/EOxElements/elements/map/examples/index.html)

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

silvester-parisantillandlubojrschpidistefanbrand

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-CYUgfrsc.js AI (source-diff): Bundled OpenLayers (ol) code, minified not obfuscated. ai
source-diff obfuscated-file:dist/eox-map-globe.js AI (source-diff): Bundled openglobus globe rendering code, minified not obfuscated. ai
source-diff obfuscated-file:dist/lerc-DNlc16Zc.js AI (source-diff): Bundled LERC image decoder, minified not obfuscated. ai
source-diff obfuscated-file:dist/decoder-CLokFc0V.js AI (source-diff): Minified bundled decoder (LERC/worker polyfill), not true obfuscation. ai
source-diff net-exec-file:dist/decoder-CLokFc0V.js AI (source-diff): Web Worker feature-detect + generator polyfill, not dropper behavior. ai
source-diff encoded-string-file:dist/eox-map-advanced-layers-and-sources.umd.cjs AI (source-diff): Long strings are minified WebGL shader source code, not encoded payloads. ai
source-diff obfuscated-file:dist/zstd-dJuUp1fl.js AI (source-diff): Emscripten WASM wrapper for numcodecs/zstd codec; minified by design. ai
source-diff obfuscated-file:dist/blosc-DL1kZHdE.js AI (source-diff): Emscripten WASM wrapper for numcodecs/blosc compression codec; minified by design. ai
source-diff obfuscated-file:dist/lerc-BRg84-C8.js AI (source-diff): Minified LERC/zstddec decoder bundle from known upstream packages; not malicious. ai
source-diff obfuscated-file:dist/lz4-Csz5aoFA.js AI (source-diff): Emscripten WASM wrapper for numcodecs/lz4 codec; minified by design. ai
source-diff obfuscated-file:dist/zstd-Cttq39rt.js AI (source-diff): Minified zstddec streaming decoder from known upstream; not malicious. ai
typosquat typosquat.levenshtein:hapi AI (typosquat): Scoped package @eox/map; Levenshtein match to 'hapi' is spurious, no squatting intent. ai
semgrep semgrep:eval-usage AI (semgrep): eval() used for documented serialize-javascript deserialization pattern; input is internally serialized layer config, not user-controlled arbitrary input. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped package @eox/map; Levenshtein match to 'yup' is spurious, no squatting intent. ai

Versions (showing 8 of 8)

Version Deps Published
2.6.0 10 / 2
2.5.1 10 / 2
2.5.0 10 / 2
2.4.0 10 / 2
2.0.1 10 / 2
2.0.0 10 / 2
1.26.3 8 / 2
1.26.2 8 / 2

v2.0.1

6 findings
HIGH New obfuscated file: dist/decoder-CLokFc0V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decoder-CLokFc0V.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/eox-map-globe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CYUgfrsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lerc-DNlc16Zc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

3 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

HIGH New obfuscated file: dist/eox-map-globe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Publisher changed: GitHub Actions → silvester-pari (on 2025-12-13, known maintainer) provenance

This version was published by a different npm account (silvester-pari) than the most recent previously approved version (GitHub Actions) on 2025-12-13, but silvester-pari is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.26.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.26.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.