← Home

@everymatrix/lottery-tipping-ticket-bet

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

clokzeoleksandr.v.stepanovtaras.maksymivnatalya.anisimovaemfe_releasemariana.gheorgheadrian.priponandriizadvirnyiraulvasileemstrulea.sebastianstefan.vladgoe.sutadragos.bodeamaria.bumbarstefanaotong.woodtikarncatalinpoclidcristi.ungureanuliviuclement.everymatrixmihaibalanfrankie24

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/esm/lottery-tipping-ticket-bet-412e5ea4.js AI (source-diff): Same Stencil.js minified bundle pattern as CJS counterpart. ai
source-diff net-exec-file:dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js AI (source-diff): Network call is CSS fetch for client styling; dynamic code execution is innerHTML for style injection — documented widget pattern. ai
source-diff obfuscated-file:dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js AI (source-diff): Standard Stencil.js minified widget bundle; long lines are minified build output, not obfuscation. ai
source-diff net-exec-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js AI (source-diff): Same CSS fetch + style injection pattern; no malicious network or exec behavior. ai
source-diff obfuscated-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js AI (source-diff): Minified Stencil.js output; content is readable widget logic with i18n strings. ai
source-diff net-exec-file:dist/esm/lottery-tipping-ticket-bet-412e5ea4.js AI (source-diff): Same CSS fetch + style injection pattern as CJS counterpart. ai
source-diff net-exec-file:dist/esm/lottery-tipping-ticket-bet-9a661560.js AI (source-diff): Network calls are CSS stylesheet fetches; dynamic code execution is innerHTML for styling — legitimate widget pattern. ai
source-diff net-exec-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-9a661560.js AI (source-diff): Network calls are CSS stylesheet fetches; dynamic code execution is innerHTML for styling — legitimate widget pattern. ai
source-diff obfuscated-file:dist/cjs/lottery-tipping-ticket-bet-18d903f5.js AI (source-diff): Standard minified Stencil widget bundle; long lines are expected build output, not obfuscation. ai
source-diff obfuscated-file:dist/esm/lottery-tipping-ticket-bet-9a661560.js AI (source-diff): Standard minified Stencil widget bundle; long lines are expected build output, not obfuscation. ai
source-diff obfuscated-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-9a661560.js AI (source-diff): Standard minified Stencil widget bundle; long lines are expected build output, not obfuscation. ai
source-diff net-exec-file:dist/cjs/lottery-tipping-ticket-bet-18d903f5.js AI (source-diff): Network calls are CSS stylesheet fetches; dynamic code execution is innerHTML for styling — legitimate widget pattern. ai
source-diff obfuscated-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-f747d889.js AI (source-diff): Minified Stencil.js bundle; long lines are expected build artifact. ai
source-diff net-exec-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-f747d889.js AI (source-diff): Same CSS-fetch pattern; not dropper malware. ai
source-diff obfuscated-file:dist/cjs/lottery-tipping-ticket-bet-d0b5966b.js AI (source-diff): Standard Stencil.js minified bundle; long lines are normal build output for this widget family. ai
source-diff net-exec-file:dist/cjs/lottery-tipping-ticket-bet-d0b5966b.js AI (source-diff): fetch+innerHTML is the documented setClientStylingURL pattern used across all @everymatrix widgets. ai
source-diff obfuscated-file:dist/esm/lottery-tipping-ticket-bet-f747d889.js AI (source-diff): Standard Stencil.js minified ESM bundle; consistent with prior versions of this package family. ai
source-diff net-exec-file:dist/esm/lottery-tipping-ticket-bet-f747d889.js AI (source-diff): Same setClientStylingURL pattern; benign CSS injection for widget theming. ai
source-diff obfuscated-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-965ce70e.js AI (source-diff): Standard minified Stencil.js build output for this widget package; not obfuscation. ai
source-diff obfuscated-file:dist/cjs/lottery-tipping-ticket-bet-1e58cff2.js AI (source-diff): Standard minified Stencil.js build output for this widget package; not obfuscation. ai
source-diff obfuscated-file:dist/esm/lottery-tipping-ticket-bet-965ce70e.js AI (source-diff): Standard minified Stencil.js build output for this widget package; not obfuscation. ai
source-diff net-exec-file:dist/cjs/lottery-tipping-ticket-bet-1e58cff2.js AI (source-diff): Network calls are CSS URL fetches; dynamic code execution is DOM style injection — legitimate widget behavior. ai
source-diff net-exec-file:dist/esm/lottery-tipping-ticket-bet-965ce70e.js AI (source-diff): Network calls are CSS URL fetches; dynamic code execution is DOM style injection — legitimate widget behavior. ai
source-diff net-exec-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-965ce70e.js AI (source-diff): Network calls are CSS URL fetches; dynamic code execution is DOM style injection — legitimate widget behavior. ai
source-diff obfuscated-file:dist/cjs/lottery-tipping-ticket-bet-392e9157.js AI (source-diff): Standard Stencil.js minified build output for this widget package; not obfuscation. ai
source-diff net-exec-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-5f448dbe.js AI (source-diff): Same setClientStylingURL fetch pattern; consistent with prior versions of this widget family. ai
source-diff obfuscated-file:dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-5f448dbe.js AI (source-diff): Minified Stencil.js bundle; long lines are expected in this build format. ai
source-diff net-exec-file:dist/esm/lottery-tipping-ticket-bet-5f448dbe.js AI (source-diff): Same setClientStylingURL pattern; legitimate widget styling API. ai
source-diff obfuscated-file:dist/esm/lottery-tipping-ticket-bet-5f448dbe.js AI (source-diff): Standard Stencil.js minified ESM build output; not obfuscation. ai
source-diff net-exec-file:dist/cjs/lottery-tipping-ticket-bet-392e9157.js AI (source-diff): fetch+innerHTML is the documented setClientStylingURL pattern for this widget family; not dropper behavior. ai
npm-metadata no-description AI (npm-metadata): Consistent across all 259 versions; intentional for this internal component library. ai
bogus-package bogus-package AI (bogus-package): Scoped corporate monorepo component; empty stubs and missing metadata are expected for this package family. ai

Versions (showing 51 of 174)

View all versions
Version Deps Published
1.94.34 0 / 0
1.94.33 0 / 0
1.94.32 0 / 0
1.94.31 0 / 0
1.94.30 0 / 0
1.94.29 0 / 0
1.94.28 0 / 0
1.94.27 0 / 0
1.94.26 0 / 0
1.94.25 0 / 0
1.94.24 0 / 0
1.94.23 0 / 0
1.94.22 0 / 0
1.94.21 0 / 0
1.94.20 0 / 0
1.94.19 0 / 0
1.94.18 0 / 0
1.94.17 0 / 0
1.94.16 0 / 0
1.94.15 0 / 0
1.94.9 0 / 0
1.94.8 0 / 0
1.94.7 0 / 0
1.94.6 0 / 0
1.94.5 0 / 0
1.94.4 0 / 0
1.94.3 0 / 0
1.94.2 0 / 0
1.94.1 0 / 0
1.94.0 0 / 0
1.93.15 0 / 0
1.93.14 0 / 0
1.93.13 0 / 0
1.93.12 0 / 0
1.93.11 0 / 0
1.93.10 0 / 0
1.93.9 0 / 0
1.93.8 0 / 0
1.93.7 0 / 0
1.93.6 0 / 0
1.93.5 0 / 0
1.93.4 0 / 0
1.93.3 0 / 0
1.93.2 0 / 0
1.93.1 0 / 0
1.93.0 0 / 0
1.92.8 0 / 0
1.92.7 0 / 0
1.92.6 0 / 0
1.92.5 0 / 0
1.92.4 0 / 0

v1.94.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.19

8 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-28, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-28, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.18

8 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-28, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-28, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.17

8 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-27, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-27, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.16

8 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-26, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-26, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.15

8 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-26, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-26, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.9

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.8

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.7

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.6

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.5

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.4

7 findings
HIGH New obfuscated file: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/lottery-tipping-ticket-bet-21a6b7bb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/esm/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/lottery-tipping-ticket-bet/lottery-tipping-ticket-bet-412e5ea4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.