← Home

@epilot/sdk

JavaScript/TypeScript SDK for epilot APIs

28
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

daniel-bot.epilotsumanth.kanakalajulian01sdrdhanttiviljamij.pinhopraneetrosureshkumarsa.kediasebas.sauerepilot-dev-toolsalexmarqsvladcrishanwmolinarij.carneironishugoeljakub.duras.epilotjulian.maurermanikandan.subramanianberni-epilotmateus.nardogokul.kalaikovan.epilotkarl.epilotpriit.parnathisisernestoepilot.ernestomarta-osowieckaepilot-blomqmagabriel.epilothelyaepilotflavius_amsergey.sedelnikov.epilotdanuta.ludwikowskaajamuar_epilotluca-felix-epilots.tothmarta.pestkafriedrich_epilotpavish.epilotbalintk-epilotankit.prasadirockelkshitij.saxena.epilotpaulo.henriquesniko.kozivjosh.stewart.epilotjoecaseepilotrichard.griffithsflorian.fuchs.epilotsimone.epilot

Keywords

epilotsdkopenapi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): CI publish metadata artifact; provenance direction unchanged. ai
source-diff obfuscated-file:dist/access-token-7Y2MDFZH.cjs AI (source-diff): tsup-bundled per-API module, not true obfuscation. ai
source-diff net-exec-file:dist/app-5VPBDFW2.cjs AI (source-diff): Contains OpenAPI JSON definitions, no actual dynamic exec/network payload. ai
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publisher with SLSA provenance is an improvement, not compromise. ai
source-diff obfuscated-file:dist/entity-RCWJZZXM.cjs AI (source-diff): Bundled API client output, minified not obfuscated. ai
provenance regressed-provenance AI (provenance): Manual publish by known maintainer already on prior versions, not a new actor. ai
source-diff obfuscated-file:dist/customer-portal-AEFMNNYP.cjs AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. ai
source-diff obfuscated-file:dist/customer-portal.d-BJNWYMt9.d.ts AI (source-diff): Generated type definitions, long lines from auto-gen, not obfuscation. ai
source-diff obfuscated-file:dist/journey-KDR5EU3W.js AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. ai
source-diff obfuscated-file:dist/customer-portal-Y3GLUVMW.js AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. ai
source-diff obfuscated-file:dist/customer-portal.d-BJNWYMt9.d.cts AI (source-diff): Generated type definitions, long lines from auto-gen, not obfuscation. ai
source-diff obfuscated-file:dist/audit-logs-D2LFUA2R.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/billing-DUWDISHP.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/blueprint-manifest-SHNZPK5O.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/app-IKHWU222.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/ai-agents-PWHKNRCX.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/address-suggestions-IUQMYF27.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/address-HA4RMRNQ.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/access-token-6BJDZSFE.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/automation-3HGCK725.cjs AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. ai
source-diff obfuscated-file:dist/erp-integration-A33WOGPF.cjs AI (source-diff): Standard tsup bundle output with readable API docs content; not obfuscated. ai
source-diff obfuscated-file:dist/erp-integration.d-B4XPU_j-.d.ts AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated. ai
source-diff obfuscated-file:dist/erp-integration-76K5HOGL.js AI (source-diff): Standard tsup ESM bundle with readable API docs content; not obfuscated. ai
source-diff obfuscated-file:dist/erp-integration.d-B4XPU_j-.d.cts AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated. ai
source-diff obfuscated-file:dist/README-6MG272KM.cjs AI (source-diff): Minified CJS bundle; standard tsup build output for this SDK. ai
source-diff obfuscated-file:dist/user-7ZN2XO7G.cjs AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. ai
source-diff obfuscated-file:dist/README-PTYV6PQI.cjs AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. ai
source-diff obfuscated-file:dist/environments-TZYXLYXA.cjs AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. ai
source-diff obfuscated-file:dist/design-NISDHPFD.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/sharing-MR7ANOST.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/template-variables-I72B5WS6.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/workflow-CQOBZ25C.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/workflow-definition-CVBYKAUY.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/automation.d-CzhG2m4L.d.cts AI (source-diff): TypeScript declaration file with large type definitions; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/blueprint-manifest-VBOWPK52.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/README-Z5AKTGJA.cjs AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. ai
source-diff obfuscated-file:dist/journey-REBN4TGQ.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/automation-IOCVCTKR.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/blueprint-manifest-IEQ6YBY7.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/configuration-hub-LKSRCGYT.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/customer-portal-5LMHNBMD.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/data-governance-2U5UU4GM.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/deduplication-PKKTZAEA.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/design-XZKOZLTR.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/email-settings-NQJJKS2P.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/entity-TFMH5VTZ.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/environments-QJ4UMJ5C.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/erp-integration-PAVHSUDM.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/erp-integration-runtime-OZ4YSTQX.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/integration-toolkit-VNMDI55O.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/message-J2SFQJNB.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
source-diff obfuscated-file:dist/query-JSDB2F2U.cjs AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. ai
maintainer-change maintainer-added AI (maintainer-change): Internal epilot GmbH team rotation; SLSA provenance confirms CI-published release. ai
maintainer-change maintainer-removed AI (maintainer-change): Internal epilot GmbH team rotation; SLSA provenance confirms CI-published release. ai
source-diff obfuscated-file:dist/targeting-67M7H7T7.cjs AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. ai
source-diff obfuscated-file:dist/blueprint-manifest-GCV7H74X.cjs AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. ai
source-diff obfuscated-file:dist/targeting-XHHZ2TK4.js AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. ai
source-diff obfuscated-file:dist/blueprint-manifest-6DEYW5MW.js AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. ai
source-diff obfuscated-file:dist/webhooks-SK2STDKR.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/README-IVBISSWB.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/pricing-F7HQ6BWC.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/notes-SLEUSNP4.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/metering-MHBFU7QH.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/journey-ATC3Y5AW.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/integration-toolkit-3I3IPVFN.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/file-BGJVE7QG.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/event-catalog-5JBHJJ2I.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/entity-SS36LQO6.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/email-settings-YJ4X5VFU.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/design-W3D3UPGB.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/customer-portal-5OSGSYGF.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/configuration-hub-Q5JBYB52.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff obfuscated-file:dist/app-74LECFMK.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code, not obfuscated malware. ai
source-diff obfuscated-file:dist/calendar-2YDAYG7S.cjs AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. ai
source-diff large-new-source-files AI (source-diff): SDK adds new API modules per version; large file count is expected growth pattern for this package. ai
source-diff net-exec-file:dist/app.d-BOR23dso.d.cts AI (source-diff): TypeScript declaration file (.d.cts); network/exec pattern is a false positive on type-level API surface definitions. ai
source-diff obfuscated-file:dist/customer-portal.d-BRwiQehb.d.cts AI (source-diff): Large TypeScript declaration file from tsup; long lines are generated type unions, not obfuscation. ai
source-diff obfuscated-file:dist/entity-RT4YRZDG.js AI (source-diff): Standard tsup ESM bundle; same pattern as CJS counterpart. ai
source-diff obfuscated-file:dist/entity.d-__Tx1Y0J.d.ts AI (source-diff): TypeScript declaration file with readable OpenAPI types; long lines from type unions. ai
source-diff obfuscated-file:dist/entity.d-__Tx1Y0J.d.cts AI (source-diff): TypeScript declaration file with readable OpenAPI types; long lines from type unions. ai
source-diff obfuscated-file:dist/entity-M5F22DSS.cjs AI (source-diff): Standard tsup CJS bundle; long lines are embedded API doc strings, not obfuscation. ai

Versions (showing 28 of 28)

Version Deps Published
2.14.2 0 / 7
2.7.7 0 / 7
2.7.6 0 / 7
2.7.5 0 / 7
2.7.4 0 / 7
2.4.3 0 / 7
2.3.7 0 / 7
2.3.6 0 / 7
2.3.5 0 / 7
2.3.2 0 / 7
2.3.1 0 / 7
2.3.0 0 / 7
2.2.7 0 / 7
2.2.6 0 / 7
2.2.5 0 / 7
2.2.2 0 / 7
2.2.1 0 / 7
2.2.0 0 / 7
2.1.10 0 / 7
2.1.9 0 / 7
2.1.8 0 / 7
2.1.7 0 / 7
2.1.6 0 / 7
2.1.5 0 / 7
2.1.4 0 / 7
2.1.0 0 / 7
2.0.4 0 / 7
2.0.3 0 / 7

v2.14.2

20 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/access-token-7Y2MDFZH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-D6C5TXLD.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-5NBZZJK2.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-C45UEPBV.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-WHYSBU66.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-JZMXGNRO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/event-catalog-6ZSSF5JU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/file-7CQXDQ3I.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/integration-toolkit-2BLX4CSH.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/journey-LHVSSVTG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/message-CEJ6VDZ6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/metering-3K36TQ5Z.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/notification-R2XBHFEW.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/pricing-BJUABPHU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/README-XCIDDEAE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/snapshot-NKK6BNQB.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/targeting-CSGKITGV.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/user-GZLPNGIW.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.6

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → anttiviljami (on 2026-04-15, known maintainer) provenance

This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-04-15, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.2

17 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH New obfuscated file: dist/customer-portal-AEFMNNYP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/entity-RCWJZZXM.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/erp-integration-6I4B4BIU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation.d-D7BzN7Gq.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/entity.d-t9R21446.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/erp-integration.d-BV3Rv9e6.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-Y3GLUVMW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/entity-X374X6EQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/erp-integration-G54BMGGE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/journey-KDR5EU3W.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation.d-D7BzN7Gq.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/entity.d-t9R21446.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/erp-integration.d-BV3Rv9e6.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Publisher changed: GitHub Actions → anttiviljami (on 2026-03-25, known maintainer) provenance

This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-25, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.1

7 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH New obfuscated file: dist/customer-portal-AEFMNNYP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-Y3GLUVMW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/journey-KDR5EU3W.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Publisher changed: GitHub Actions → anttiviljami (on 2026-03-24, known maintainer) provenance

This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-24, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.2.0

7 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH New obfuscated file: dist/customer-portal-AEFMNNYP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-Y3GLUVMW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/journey-KDR5EU3W.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Publisher changed: GitHub Actions → anttiviljami (on 2026-03-24, known maintainer) provenance

This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-24, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.10

6 findings
HIGH New obfuscated file: dist/customer-portal-AEFMNNYP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-Y3GLUVMW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/journey-KDR5EU3W.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.9

5 findings
HIGH New obfuscated file: dist/customer-portal-AEFMNNYP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal-Y3GLUVMW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/customer-portal.d-BJNWYMt9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.7

13 findings
HIGH Publisher changed: epilot-dev-tools → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/access-token-6BJDZSFE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-HA4RMRNQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-suggestions-IUQMYF27.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-PWHKNRCX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/app-5VPBDFW2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/app-PL3IOROO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/audit-logs-D2LFUA2R.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-3HGCK725.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-HZASSUCS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-DUWDISHP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-SHNZPK5O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.6

13 findings
HIGH Publisher changed: epilot-dev-tools → GitHub Actions (on 2026-03-23) provenance

This version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/access-token-6BJDZSFE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-HA4RMRNQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-suggestions-IUQMYF27.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-PWHKNRCX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/app-5VPBDFW2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/app-PL3IOROO.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/audit-logs-D2LFUA2R.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-3HGCK725.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-HZASSUCS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-DUWDISHP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-SHNZPK5O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.5

13 findings
HIGH Publisher changed: epilot-dev-tools → GitHub Actions (on 2026-03-22) provenance

This version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/access-token-6BJDZSFE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-HA4RMRNQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-suggestions-IUQMYF27.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-PWHKNRCX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/app-5VPBDFW2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/app-IKHWU222.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/audit-logs-D2LFUA2R.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-3HGCK725.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-HZASSUCS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-DUWDISHP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-SHNZPK5O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.4

13 findings
HIGH Publisher changed: epilot-dev-tools → GitHub Actions (on 2026-03-20) provenance

This version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/access-token-6BJDZSFE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-HA4RMRNQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-suggestions-IUQMYF27.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-PWHKNRCX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/app-5VPBDFW2.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/app-IKHWU222.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/audit-logs-D2LFUA2R.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-3HGCK725.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-HZASSUCS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-DUWDISHP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-SHNZPK5O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

10 findings
HIGH New obfuscated file: dist/access-token-6BJDZSFE.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-HA4RMRNQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/address-suggestions-IUQMYF27.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ai-agents-PWHKNRCX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-IKHWU222.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/audit-logs-D2LFUA2R.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/automation-3HGCK725.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/billing-DUWDISHP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/blueprint-manifest-SHNZPK5O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.