← Home

@feedmepos/mf-menu

# mf-menu

21
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

victor.chailokingweidanielmcfluffy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/App-DIECU1uj.js AI (source-diff): Bundled app code with normal fetch/vue usage, no dropper behavior. ai
source-diff obfuscated-file:dist/assets/menu-export-BFG97Uh7.js AI (source-diff): Bundled build chunk. ai
source-diff obfuscated-file:dist/assets/linked-status-BQ4Atqaz.js AI (source-diff): Bundled build chunk. ai
source-diff net-exec-file:dist/jszip.min-DXGEsthp.js AI (source-diff): Minified jszip lib, no malicious behavior. ai
source-diff obfuscated-file:dist/jszip.min-DXGEsthp.js AI (source-diff): jszip minified library bundle. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-z_iUiIXp.js AI (source-diff): CI env dump is a baked-in build artifact/log, not exfil code; rest is bundled Vue output. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js AI (source-diff): Bundled output, standard firebase/vue SDK code. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js AI (source-diff): Bundled Vue/Firebase/Pinia app chunk. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js AI (source-diff): Bundled output, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js AI (source-diff): Bundled Vue SFC output with xlsx lib inlined. ai
source-diff obfuscated-file:dist/app-Gu39_jfp.js AI (source-diff): Bundled Vue component output. ai
source-diff obfuscated-file:dist/App-DIECU1uj.js AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-CK-Ihn0s.js AI (source-diff): Bundled Vue SFC output. ai
source-diff obfuscated-file:dist/assets/override-menu-BxetmhPm.js AI (source-diff): Bundled build chunk. ai
phantom-deps phantom-dep-scan-truncated AI (phantom-deps): Large bundled Vue dist output; truncation expected for this package's size, not evasion. ai
dependencies unvetted-dep:@feedmepos/remy-vue-client AI (dependencies): First-party FeedMePOS scoped dep, consistent with monorepo pattern. ai
source-diff net-exec-file:dist/jszip.min-BhA-u0sg.js AI (source-diff): jszip library code, not a loader. ai
source-diff obfuscated-file:dist/jszip.min-BhA-u0sg.js AI (source-diff): Third-party jszip minified lib, declared dependency. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js AI (source-diff): Bundled dependencies triggering pattern match, no concrete malicious dest. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js AI (source-diff): Core bundled chunk incl. dayjs; minified build output. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js AI (source-diff): Same bundled xlsx dependency, no malicious behavior. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js AI (source-diff): Bundles xlsx.js library, minified not obfuscated. ai
source-diff net-exec-file:dist/App-DfUun7yx.js AI (source-diff): Firebase SDK bundled in; network+eval pattern is library code, not a dropper. ai
source-diff obfuscated-file:dist/App-DfUun7yx.js AI (source-diff): Bundled Vue/Firebase app entry, minified not obfuscated. ai
source-diff obfuscated-file:dist/app-CyW5XJI3.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js AI (source-diff): Firebase SDK network calls; no hostile destination. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-CRLzqgQe.js AI (source-diff): Vite-bundled Vue component chunk; standard minified output. ai
source-diff obfuscated-file:dist/assets/override-menu-BJGRdWWE.js AI (source-diff): Vite-bundled asset chunk; standard minified output. ai
source-diff obfuscated-file:dist/assets/menu-export-DxtFXMED.js AI (source-diff): Vite-bundled asset chunk; standard minified output. ai
source-diff obfuscated-file:dist/assets/linked-status-WT6deoPw.js AI (source-diff): Vite-bundled asset chunk; standard minified output. ai
source-diff net-exec-file:dist/jszip.min-1MrCGuHF.js AI (source-diff): JSZip uses dynamic patterns internally; no hostile network destination. ai
source-diff obfuscated-file:dist/jszip.min-1MrCGuHF.js AI (source-diff): JSZip minified library — expected long-line bundled output. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-CXHHlrI0.js AI (source-diff): Bundled output; leaked CI env vars are a build artifact, not malicious behavior. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js AI (source-diff): Vite-bundled main chunk; dayjs/pinia/Vue readable code, not obfuscated. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js AI (source-diff): Network calls are part of SheetJS/Firebase; no hostile destination. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js AI (source-diff): Bundled output containing xlsx.js (SheetJS) — well-known library, not obfuscation. ai
source-diff net-exec-file:dist/App-CczmyQeJ.js AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith CJS wrapper pattern — no hostile destination. ai
source-diff obfuscated-file:dist/App-CczmyQeJ.js AI (source-diff): Vite-bundled ESM output; readable Vue/Firebase/flagsmith code. ai
source-diff obfuscated-file:dist/app-CA4g3v2n.js AI (source-diff): Vite-bundled ESM output; readable Vue/router code, not true obfuscation. ai
dependencies unvetted-dep:canvas AI (dependencies): Well-known canvas binding; no malicious behavior. ai
dependencies unvetted-dep:xlsx AI (dependencies): Well-known spreadsheet library; no malicious behavior. ai
phantom-deps phantom-dep:@feedmepos/feature-flag AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. ai
phantom-deps phantom-dep:@feedmepos/core-legacy AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. ai
npm-metadata url-dep:@feedmepos/mf-inventory-portal AI (npm-metadata): Direct npmjs.org tarball URL for a first-party dev package; consistent with internal tooling. ai
npm-metadata url-dep:@feedmepos/core-legacy AI (npm-metadata): file: path is a monorepo build artifact; stable pattern for this package. ai
dependencies unvetted-dep:@feedmepos/custom-attributes AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/core AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/inventory-core AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/feature-flag AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/core-legacy AI (dependencies): First-party org package; file: path is a monorepo artifact. ai
dependencies unvetted-dep:@feedmepos/zod-entity AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/menu AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
dependencies unvetted-dep:@feedmepos/core-dart AI (dependencies): First-party org package; consistent across versions of this monorepo. ai
phantom-deps phantom-dep:@feedmepos/inventory-core AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. ai
source-diff obfuscated-file:dist/App-ueXpH5uy.js AI (source-diff): Minified Vite bundle; imports confirm Vue/Firebase/flagsmith, no malicious indicators. ai
source-diff obfuscated-file:dist/app-4a-p2oXw.js AI (source-diff): Standard Vite-minified Vue bundle; readable imports confirm legitimate library code. ai
source-diff net-exec-file:dist/App-ueXpH5uy.js AI (source-diff): Flagsmith SDK + Firebase bundled output; network+eval pattern is from legitimate third-party libs. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-CKOiT-Dq.js AI (source-diff): SheetJS (xlsx 0.18.5) bundled inline; recognizable library, not obfuscated malware. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-CKOiT-Dq.js AI (source-diff): SheetJS network+eval pattern is a known false positive for this library. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-bYbEuWK0.js AI (source-diff): Minified Vue component bundle with dayjs; standard build output. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-bYbEuWK0.js AI (source-diff): dayjs/Firebase bundled eval pattern; legitimate library code. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Cp-Lhe6Y.js AI (source-diff): Minified Vue component; leaked CI env vars are a build hygiene issue, not runtime malware. ai
source-diff obfuscated-file:dist/jszip.min-DnWM7-sF.js AI (source-diff): JSZip minified distribution; well-known library. ai
source-diff net-exec-file:dist/jszip.min-DnWM7-sF.js AI (source-diff): JSZip uses dynamic patterns internally; stable false positive for this package. ai
source-diff obfuscated-file:dist/assets/linked-status-BAAoFylt.js AI (source-diff): Minified Vite asset bundle; standard build output. ai
source-diff obfuscated-file:dist/assets/menu-export-Dild-wkg.js AI (source-diff): Minified Vite asset bundle; standard build output. ai
source-diff obfuscated-file:dist/assets/override-menu-DW8WHLlm.js AI (source-diff): Minified Vite asset bundle; standard build output. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-lO4l5Ljh.js AI (source-diff): Minified Vue component bundle; standard build output. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Ci-CaBED.js AI (source-diff): Minified Vue component; leaked CI env vars are build hygiene issue, not consumer threat. ai
source-diff obfuscated-file:dist/jszip.min-BiRK-xY3.js AI (source-diff): JSZip minified library; expected build artifact. ai
source-diff net-exec-file:dist/jszip.min-BiRK-xY3.js AI (source-diff): JSZip uses dynamic patterns internally; no network exfiltration. ai
source-diff obfuscated-file:dist/assets/linked-status-68qGGp41.js AI (source-diff): Vite-minified asset bundle; standard build output. ai
source-diff obfuscated-file:dist/assets/menu-export-CRtF4W1I.js AI (source-diff): Vite-minified asset bundle; standard build output. ai
source-diff obfuscated-file:dist/assets/override-menu-DB0DJf_x.js AI (source-diff): Vite-minified asset bundle; standard build output. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-DyiwvQnC.js AI (source-diff): Firebase SDK network calls; CJS interop pattern, not malware. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-Cc_k57qi.js AI (source-diff): Minified Vue component; standard build output. ai
source-diff obfuscated-file:dist/app-BC-PDZ1J.js AI (source-diff): Standard Vite-minified Vue3 bundle; readable imports from feedmepos org packages. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-DyiwvQnC.js AI (source-diff): Main bundle with dayjs/pinia/Firebase; standard Vite minification. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-DPAxkce6.js AI (source-diff): SheetJS and Vue component; no dropper pattern. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-DPAxkce6.js AI (source-diff): Minified Vue component bundle including SheetJS xlsx; legitimate build output. ai
source-diff net-exec-file:dist/App-Bt5lFavE.js AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith CJS wrapper pattern. ai
source-diff obfuscated-file:dist/App-Bt5lFavE.js AI (source-diff): Minified Vue3 app bundle with Firebase/flagsmith; no malicious payload. ai
source-diff large-new-source-files AI (source-diff): Large bundle count is expected for a micro-frontend with many Vue components and bundled deps. ai
source-diff obfuscated-file:dist/assets/linked-status-DojmxFzq.js AI (source-diff): Standard Vite minified asset bundle. ai
source-diff obfuscated-file:dist/jszip.min-OZZMb1gD.js AI (source-diff): jszip minified library bundle; expected artifact. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Cnq9QAeQ.js AI (source-diff): Minified Vue component; CI env vars baked in are a build hygiene issue, not malware. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-IHmRgZTC.js AI (source-diff): Firebase SDK network calls; commonjs interop dynamic execution is standard bundler pattern. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-IHmRgZTC.js AI (source-diff): Main bundle with Firebase/pinia/dayjs; standard Vite minification. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-hEPchEwW.js AI (source-diff): xlsx.js bundled library; network+exec pattern is false positive for this build artifact. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-hEPchEwW.js AI (source-diff): Minified Vue component bundle including xlsx.js; standard build output. ai
source-diff net-exec-file:dist/App-DqpxV0zp.js AI (source-diff): Network calls are Firebase SDK; dynamic execution is flagsmith/commonjs interop pattern, not dropper behavior. ai
source-diff obfuscated-file:dist/App-DqpxV0zp.js AI (source-diff): Standard Vite minified output; samples show Vue/Firebase/flagsmith bundle, no malicious patterns. ai
source-diff obfuscated-file:dist/app-BSpY6Pgy.js AI (source-diff): Standard Vite minified output for feedmepos Vue micro-frontend; consistent across versions. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-01qpukRE.js AI (source-diff): Standard Vite minified Vue component bundle. ai
source-diff obfuscated-file:dist/assets/override-menu-CVjWw9he.js AI (source-diff): Standard Vite minified asset bundle. ai
source-diff obfuscated-file:dist/assets/menu-export-rmsdV9dK.js AI (source-diff): Standard Vite minified asset bundle. ai
source-diff net-exec-file:dist/jszip.min-OZZMb1gD.js AI (source-diff): jszip is a legitimate compression library; false positive for net-exec rule. ai
source-diff obfuscated-file:dist/app-BU6wILmn.js AI (source-diff): Standard Vite minified bundle output for this org's micro-frontend; not intentional obfuscation. ai
source-diff obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-DaCVUn1i.js AI (source-diff): Standard Vite minified bundle output. ai
source-diff obfuscated-file:dist/assets/override-menu-CASoFjhZ.js AI (source-diff): Standard Vite minified bundle output. ai
source-diff obfuscated-file:dist/assets/menu-export-CpcyYnR-.js AI (source-diff): Standard Vite minified bundle output. ai
source-diff obfuscated-file:dist/assets/linked-status-DTIHdzDw.js AI (source-diff): Standard Vite minified bundle output. ai
source-diff net-exec-file:dist/jszip.min-DlpCmtaR.js AI (source-diff): jszip is a well-known library; no malicious pattern. ai
source-diff obfuscated-file:dist/jszip.min-DlpCmtaR.js AI (source-diff): jszip minified library bundled via Vite. ai
source-diff obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-DzzwwdA_.js AI (source-diff): Standard Vite bundle; leaked CI env vars are a hygiene issue, not malware. ai
source-diff net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-DSZsSghE.js AI (source-diff): Firebase SDK + dayjs bundled; no malicious pattern. ai
source-diff obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-DSZsSghE.js AI (source-diff): Standard Vite minified bundle output. ai
source-diff net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-Dpx4meDa.js AI (source-diff): xlsx library bundled via Vite; no malicious network/exec pattern. ai
source-diff obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-Dpx4meDa.js AI (source-diff): Standard Vite minified bundle; xlsx library bundled inline. ai
source-diff net-exec-file:dist/App-C9b4SjED.js AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith feature-flag SDK bundled via Vite. ai
source-diff obfuscated-file:dist/App-C9b4SjED.js AI (source-diff): Standard Vite minified bundle output. ai
phantom-deps phantom-dep:change-case AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:dotenv-cli AI (phantom-deps): CLI tool used in scripts; not imported in source. ai
phantom-deps phantom-dep:vue-i18n AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:firebase AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:i18next AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:exceljs AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:lodash AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:canvas AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:jszip AI (phantom-deps): Same monorepo MFE pattern; not a real missing import. ai
phantom-deps phantom-dep:@feedmepos/zod-entity AI (phantom-deps): Internal org package; MFE federation boundary. ai
phantom-deps phantom-dep:@types/dinero.js AI (phantom-deps): Type-only package; not imported at runtime. ai
phantom-deps phantom-dep:vite-svg-loader AI (phantom-deps): Build-time plugin; not imported in runtime source. ai
phantom-deps phantom-dep:@feedmepos/auth AI (phantom-deps): Internal org package; MFE federation boundary explains phantom detection. ai
phantom-deps phantom-dep:vue3-carousel AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:vuedraggable AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:vue3-lottie AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Large monorepo MFE; phantom deps are expected due to shared module federation boundaries. ai
phantom-deps phantom-dep:i18next-vue AI (phantom-deps): Same monorepo MFE pattern. ai
phantom-deps phantom-dep:file-saver AI (phantom-deps): Same monorepo MFE pattern. ai

Versions (showing 21 of 21)

Version Deps Published
0.32.59 42 / 23
0.32.58 42 / 23
0.32.52 42 / 23
0.32.45 41 / 23
0.32.43 41 / 23
0.32.41 40 / 23
0.32.39 40 / 23
0.32.37 40 / 23
0.32.36 40 / 23
0.32.34 40 / 23
0.32.33 40 / 23
0.32.31 40 / 23
0.32.29 40 / 23
0.32.27 40 / 23
0.32.26 40 / 23
0.32.25 40 / 23
0.32.24 40 / 23
0.32.22 40 / 23
0.32.8 40 / 24
0.31.74 39 / 24
0.31.59 39 / 24

v0.32.59

15 findings
HIGH New obfuscated file: dist/App-DIECU1uj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/App-DIECU1uj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/app-Gu39_jfp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/InventoryBinding.vue_vue_type_script_setup_true_lang-z_iUiIXp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jszip.min-DXGEsthp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jszip.min-DXGEsthp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/linked-status-BQ4Atqaz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/menu-export-BFG97Uh7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/override-menu-BxetmhPm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/RuleView.vue_vue_type_script_setup_true_lang-CK-Ihn0s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.58

15 findings
HIGH New obfuscated file: dist/app-CyW5XJI3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/App-DfUun7yx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/App-DfUun7yx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/InventoryBinding.vue_vue_type_script_setup_true_lang-B3fjn3Eq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jszip.min-BhA-u0sg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jszip.min-BhA-u0sg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/linked-status-U1wmb4W5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/menu-export-T0iXp2XS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/override-menu-Bebekq7W.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/RuleView.vue_vue_type_script_setup_true_lang-BNwtSwXa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.45

15 findings
HIGH New obfuscated file: dist/app-CA4g3v2n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/App-CczmyQeJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/App-CczmyQeJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/InventoryBinding.vue_vue_type_script_setup_true_lang-CXHHlrI0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jszip.min-1MrCGuHF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jszip.min-1MrCGuHF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/linked-status-WT6deoPw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/menu-export-DxtFXMED.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/override-menu-BJGRdWWE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/RuleView.vue_vue_type_script_setup_true_lang-CRLzqgQe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.32.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.31.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.31.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.