← Home

@everymatrix/player-account-product-restriction

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

clokzeoleksandr.v.stepanovtaras.maksymivnatalya.anisimovaemfe_releasemariana.gheorgheadrian.priponandriizadvirnyiraulvasileemstrulea.sebastianstefan.vladgoe.sutadragos.bodeamaria.bumbarstefanaotong.woodtikarncatalinpoclidliviuclement.everymatrixmihaibalanfrankie24

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:stencil/index-b2193545-CQaBo5im.cjs AI (source-diff): Standard StencilJS runtime bundle output; minified but not obfuscated. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-pwUhTR-f.js AI (source-diff): ES2015 variant of component bundle; standard minification. ai
source-diff obfuscated-file:components/PlayerAccountModal-CqEpJwSs.cjs AI (source-diff): Bundled Svelte modal component; standard minification. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CxUoTI7b.cjs AI (source-diff): Bundled component with dayjs; standard minification. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CxUoTI7b.cjs AI (source-diff): Vaadin dev-mode new Function() + fetch for API data; not malicious. ai
source-diff obfuscated-file:stencil/ui-skeleton-ed169f8f-cGTgZqRU.cjs AI (source-diff): StencilJS skeleton UI component; CSS + registration code. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-Cf_tzrkz.js AI (source-diff): ESM variant of Svelte bundle; same pattern as CJS counterpart. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-CXBLwcDq.js AI (source-diff): ESM Svelte bundle variant; standard minification. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CeaacUZM.js AI (source-diff): ESM variant of main component bundle; standard minification. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CeaacUZM.js AI (source-diff): Same Vaadin dev-mode + fetch pattern as CJS variant. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-C-IlBVCv.cjs AI (source-diff): Bundled Svelte component output; standard minification pattern. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-pwUhTR-f.js AI (source-diff): Same Vaadin dev-mode + fetch pattern as other variants. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-DpnTYl2R.cjs AI (source-diff): UI component with fetch + vaadin new Function(); not malicious. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-DM3iJdli.cjs AI (source-diff): Standard minified CJS build output for Svelte UI component; stable pattern for this package. ai
source-diff obfuscated-file:components/PlayerAccountModal-CaflKyjZ.cjs AI (source-diff): Minified CJS build output; stable for this package. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-DpnTYl2R.cjs AI (source-diff): Minified CJS build output; stable for this package. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-CR6AoSyA.js AI (source-diff): Minified ESM build output; stable for this package. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-mfKyZsdG.js AI (source-diff): Minified ESM build output; stable for this package. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-BrDntLjc.js AI (source-diff): Minified ESM build output; stable for this package. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-yD3kGq6y.js AI (source-diff): UI component with fetch + vaadin new Function(); not malicious. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-BrDntLjc.js AI (source-diff): UI component with fetch + vaadin new Function(); not malicious. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-yD3kGq6y.js AI (source-diff): Minified ESM build output; stable for this package. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-D3MYuu22.js AI (source-diff): Same framework-level patterns as sibling bundle; stable false positive for this package. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CO2WBgFr.js AI (source-diff): Standard minified Svelte/Stencil bundle; pattern is stable across versions of this package. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-D3MYuu22.js AI (source-diff): Standard minified Svelte/Stencil bundle; pattern is stable across versions of this package. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-C8EJriT-.js AI (source-diff): Minified modal component importing from the main bundle; no malicious indicators. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-DYp8Sm0g.js AI (source-diff): Minified modal component importing from the main bundle; no malicious indicators. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CO2WBgFr.js AI (source-diff): Network calls and dynamic execution are framework-level patterns (fetch for API, new Function in vaadin dev-mode detector); not dropper behavior. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CaOJO8qE.js AI (source-diff): Standard bundled ESM output; stable for this package. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-Dp_jAsHW.cjs AI (source-diff): Standard bundled/minified CJS output (dayjs, Vaadin); stable for this package. ai
provenance publisher-changed AI (provenance): Both emfe_release and adrian.pripon are known @everymatrix publishers. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-ClFmYUCl.js AI (source-diff): Bundle contains fetch + new Function from Vaadin; not malicious. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CaOJO8qE.js AI (source-diff): Bundle contains fetch + new Function from Vaadin; not malicious. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-Dp_jAsHW.cjs AI (source-diff): Bundle contains fetch + new Function from Vaadin; not malicious. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-ClFmYUCl.js AI (source-diff): Standard bundled ESM output; stable for this package. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-DT9tTM1d.js AI (source-diff): Network/exec pattern consistent with Svelte component fetch and lifecycle; not malicious. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-DjoR1ciT.cjs AI (source-diff): Standard Rollup/Vite minified build output for Svelte components; consistent with this package's established build pipeline. ai
source-diff obfuscated-file:components/PlayerAccountModal-DT8jP5ZF.cjs AI (source-diff): Standard Rollup/Vite minified build output; Svelte runtime patterns clearly visible in sample. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CHi2R6Ax.cjs AI (source-diff): Standard Rollup/Vite minified build output; dayjs and Svelte internals visible in sample. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CHi2R6Ax.cjs AI (source-diff): Network calls are dayjs/Svelte fetch patterns; dynamic execution is Svelte component lifecycle, not dropper behavior. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-Dsb3QBRi.js AI (source-diff): Standard Vite/Rollup minified Svelte build output. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-DuVksImo.js AI (source-diff): Standard Vite/Rollup minified Svelte build output. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-D1tQkRwh.js AI (source-diff): Standard Vite/Rollup minified Svelte build output with dayjs bundled inline. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-D1tQkRwh.js AI (source-diff): Network/exec pattern is Svelte component lifecycle and dayjs; not malicious dropper behavior. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-DT9tTM1d.js AI (source-diff): Standard Vite/Rollup minified Svelte build output. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-CQT_xWWw.cjs AI (source-diff): Standard Svelte/Vite minified bundle output; consistent with prior versions of this package. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-BuSlptBE.js AI (source-diff): Network calls are fetch-based API calls; dynamic execution is requestAnimationFrame/Promise — standard Svelte runtime patterns. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-BuSlptBE.js AI (source-diff): Standard Svelte/Vite minified bundle output. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-bGcl5Pri.js AI (source-diff): Network calls are fetch-based API calls; dynamic execution is requestAnimationFrame/Promise — standard Svelte runtime patterns. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-bGcl5Pri.js AI (source-diff): Standard Svelte/Vite minified bundle output. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-BXbMEIyB.js AI (source-diff): Standard Svelte/Vite minified bundle output. ai
source-diff obfuscated-file:components/PlayerAccountGeneralConfirmationModal-2Px9jd0g.js AI (source-diff): Standard Svelte/Vite minified bundle output. ai
source-diff net-exec-file:components/PlayerAccountProductRestriction-CJzS_5ta.cjs AI (source-diff): Network calls are fetch-based API calls; dynamic execution is requestAnimationFrame/Promise — standard Svelte runtime patterns. ai
source-diff obfuscated-file:components/PlayerAccountProductRestriction-CJzS_5ta.cjs AI (source-diff): Standard Svelte/Vite minified bundle output; consistent with prior versions of this package. ai
source-diff obfuscated-file:components/PlayerAccountModal-BBWEDNSU.cjs AI (source-diff): Standard Svelte/Vite minified bundle output; consistent with prior versions of this package. ai
bogus-package bogus-package AI (bogus-package): Scoped monorepo component package; missing metadata is consistent across all 285 versions. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled Vaadin dev-mode detector; stable false positive for this component package. ai

Versions (showing 51 of 216)

View all versions
Version Deps Published
1.94.32 0 / 0
1.94.31 0 / 0
1.94.30 0 / 0
1.94.29 0 / 0
1.94.28 0 / 0
1.94.27 0 / 0
1.94.26 0 / 0
1.94.25 0 / 0
1.94.24 0 / 0
1.94.23 0 / 0
1.94.22 0 / 0
1.94.21 0 / 0
1.94.20 0 / 0
1.94.19 0 / 0
1.94.18 0 / 0
1.94.17 0 / 0
1.94.16 0 / 0
1.94.15 0 / 0
1.94.9 0 / 0
1.94.8 0 / 0
1.94.7 0 / 0
1.94.6 0 / 0
1.94.5 0 / 0
1.94.4 0 / 0
1.94.3 0 / 0
1.94.2 0 / 0
1.94.1 0 / 0
1.94.0 0 / 0
1.93.15 0 / 0
1.93.14 0 / 0
1.93.13 0 / 0
1.93.12 0 / 0
1.93.11 0 / 0
1.93.10 0 / 0
1.93.9 0 / 0
1.93.8 0 / 0
1.93.7 0 / 0
1.93.6 0 / 0
1.93.5 0 / 0
1.93.4 0 / 0
1.93.3 0 / 0
1.93.2 0 / 0
1.93.1 0 / 0
1.93.0 0 / 0
1.92.8 0 / 0
1.92.7 0 / 0
1.92.6 0 / 0
1.92.5 0 / 0
1.92.4 0 / 0
1.92.3 0 / 0
1.92.2 0 / 0

v1.94.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.15

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adrian.pripon → goe.suta (on 2026-05-26, known maintainer) provenance

This version was published by a different npm account (goe.suta) than the most recent previously approved version (adrian.pripon) on 2026-05-26, but goe.suta is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.8

7 findings
HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-C8EJriT-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-DYp8Sm0g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.7

11 findings
HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-CQT_xWWw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountModal-BBWEDNSU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-C8EJriT-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-DYp8Sm0g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.6

11 findings
HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-CQT_xWWw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountModal-BBWEDNSU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-C8EJriT-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-DYp8Sm0g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.5

11 findings
HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-CQT_xWWw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountModal-BBWEDNSU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-C8EJriT-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-DYp8Sm0g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CO2WBgFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-D3MYuu22.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.4

11 findings
HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-CQT_xWWw.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountModal-BBWEDNSU.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-CJzS_5ta.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-2Px9jd0g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountGeneralConfirmationModal-BXbMEIyB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-bGcl5Pri.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-bGcl5Pri.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: components/PlayerAccountProductRestriction-BuSlptBE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: components/PlayerAccountProductRestriction-BuSlptBE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.94.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.93.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.92.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.