@feedmepos/mf-menu
# mf-menu
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/App-DIECU1uj.js | AI (source-diff): Bundled app code with normal fetch/vue usage, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-BFG97Uh7.js | AI (source-diff): Bundled build chunk. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-BQ4Atqaz.js | AI (source-diff): Bundled build chunk. | ai | |
| source-diff | net-exec-file:dist/jszip.min-DXGEsthp.js | AI (source-diff): Minified jszip lib, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-DXGEsthp.js | AI (source-diff): jszip minified library bundle. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-z_iUiIXp.js | AI (source-diff): CI env dump is a baked-in build artifact/log, not exfil code; rest is bundled Vue output. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js | AI (source-diff): Bundled output, standard firebase/vue SDK code. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-4QceDakZ.js | AI (source-diff): Bundled Vue/Firebase/Pinia app chunk. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js | AI (source-diff): Bundled output, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-x4ZPqRIM.js | AI (source-diff): Bundled Vue SFC output with xlsx lib inlined. | ai | |
| source-diff | obfuscated-file:dist/app-Gu39_jfp.js | AI (source-diff): Bundled Vue component output. | ai | |
| source-diff | obfuscated-file:dist/App-DIECU1uj.js | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-CK-Ihn0s.js | AI (source-diff): Bundled Vue SFC output. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-BxetmhPm.js | AI (source-diff): Bundled build chunk. | ai | |
| phantom-deps | phantom-dep-scan-truncated | AI (phantom-deps): Large bundled Vue dist output; truncation expected for this package's size, not evasion. | ai | |
| dependencies | unvetted-dep:@feedmepos/remy-vue-client | AI (dependencies): First-party FeedMePOS scoped dep, consistent with monorepo pattern. | ai | |
| source-diff | net-exec-file:dist/jszip.min-BhA-u0sg.js | AI (source-diff): jszip library code, not a loader. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-BhA-u0sg.js | AI (source-diff): Third-party jszip minified lib, declared dependency. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js | AI (source-diff): Bundled dependencies triggering pattern match, no concrete malicious dest. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-D1e43ULb.js | AI (source-diff): Core bundled chunk incl. dayjs; minified build output. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js | AI (source-diff): Same bundled xlsx dependency, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-X7civFqp.js | AI (source-diff): Bundles xlsx.js library, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/App-DfUun7yx.js | AI (source-diff): Firebase SDK bundled in; network+eval pattern is library code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/App-DfUun7yx.js | AI (source-diff): Bundled Vue/Firebase app entry, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/app-CyW5XJI3.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js | AI (source-diff): Firebase SDK network calls; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-CRLzqgQe.js | AI (source-diff): Vite-bundled Vue component chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-BJGRdWWE.js | AI (source-diff): Vite-bundled asset chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-DxtFXMED.js | AI (source-diff): Vite-bundled asset chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-WT6deoPw.js | AI (source-diff): Vite-bundled asset chunk; standard minified output. | ai | |
| source-diff | net-exec-file:dist/jszip.min-1MrCGuHF.js | AI (source-diff): JSZip uses dynamic patterns internally; no hostile network destination. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-1MrCGuHF.js | AI (source-diff): JSZip minified library — expected long-line bundled output. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-CXHHlrI0.js | AI (source-diff): Bundled output; leaked CI env vars are a build artifact, not malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-C6IVvAua.js | AI (source-diff): Vite-bundled main chunk; dayjs/pinia/Vue readable code, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js | AI (source-diff): Network calls are part of SheetJS/Firebase; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-C903fhuj.js | AI (source-diff): Bundled output containing xlsx.js (SheetJS) — well-known library, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/App-CczmyQeJ.js | AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith CJS wrapper pattern — no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/App-CczmyQeJ.js | AI (source-diff): Vite-bundled ESM output; readable Vue/Firebase/flagsmith code. | ai | |
| source-diff | obfuscated-file:dist/app-CA4g3v2n.js | AI (source-diff): Vite-bundled ESM output; readable Vue/router code, not true obfuscation. | ai | |
| dependencies | unvetted-dep:canvas | AI (dependencies): Well-known canvas binding; no malicious behavior. | ai | |
| dependencies | unvetted-dep:xlsx | AI (dependencies): Well-known spreadsheet library; no malicious behavior. | ai | |
| phantom-deps | phantom-dep:@feedmepos/feature-flag | AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. | ai | |
| phantom-deps | phantom-dep:@feedmepos/core-legacy | AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. | ai | |
| npm-metadata | url-dep:@feedmepos/mf-inventory-portal | AI (npm-metadata): Direct npmjs.org tarball URL for a first-party dev package; consistent with internal tooling. | ai | |
| npm-metadata | url-dep:@feedmepos/core-legacy | AI (npm-metadata): file: path is a monorepo build artifact; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@feedmepos/custom-attributes | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/core | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/inventory-core | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/feature-flag | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/core-legacy | AI (dependencies): First-party org package; file: path is a monorepo artifact. | ai | |
| dependencies | unvetted-dep:@feedmepos/zod-entity | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/menu | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| dependencies | unvetted-dep:@feedmepos/core-dart | AI (dependencies): First-party org package; consistent across versions of this monorepo. | ai | |
| phantom-deps | phantom-dep:@feedmepos/inventory-core | AI (phantom-deps): First-party monorepo dep; phantom detection is a false positive here. | ai | |
| source-diff | obfuscated-file:dist/App-ueXpH5uy.js | AI (source-diff): Minified Vite bundle; imports confirm Vue/Firebase/flagsmith, no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/app-4a-p2oXw.js | AI (source-diff): Standard Vite-minified Vue bundle; readable imports confirm legitimate library code. | ai | |
| source-diff | net-exec-file:dist/App-ueXpH5uy.js | AI (source-diff): Flagsmith SDK + Firebase bundled output; network+eval pattern is from legitimate third-party libs. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-CKOiT-Dq.js | AI (source-diff): SheetJS (xlsx 0.18.5) bundled inline; recognizable library, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-CKOiT-Dq.js | AI (source-diff): SheetJS network+eval pattern is a known false positive for this library. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-bYbEuWK0.js | AI (source-diff): Minified Vue component bundle with dayjs; standard build output. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-bYbEuWK0.js | AI (source-diff): dayjs/Firebase bundled eval pattern; legitimate library code. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Cp-Lhe6Y.js | AI (source-diff): Minified Vue component; leaked CI env vars are a build hygiene issue, not runtime malware. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-DnWM7-sF.js | AI (source-diff): JSZip minified distribution; well-known library. | ai | |
| source-diff | net-exec-file:dist/jszip.min-DnWM7-sF.js | AI (source-diff): JSZip uses dynamic patterns internally; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-BAAoFylt.js | AI (source-diff): Minified Vite asset bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-Dild-wkg.js | AI (source-diff): Minified Vite asset bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-DW8WHLlm.js | AI (source-diff): Minified Vite asset bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-lO4l5Ljh.js | AI (source-diff): Minified Vue component bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Ci-CaBED.js | AI (source-diff): Minified Vue component; leaked CI env vars are build hygiene issue, not consumer threat. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-BiRK-xY3.js | AI (source-diff): JSZip minified library; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/jszip.min-BiRK-xY3.js | AI (source-diff): JSZip uses dynamic patterns internally; no network exfiltration. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-68qGGp41.js | AI (source-diff): Vite-minified asset bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-CRtF4W1I.js | AI (source-diff): Vite-minified asset bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-DB0DJf_x.js | AI (source-diff): Vite-minified asset bundle; standard build output. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-DyiwvQnC.js | AI (source-diff): Firebase SDK network calls; CJS interop pattern, not malware. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-Cc_k57qi.js | AI (source-diff): Minified Vue component; standard build output. | ai | |
| source-diff | obfuscated-file:dist/app-BC-PDZ1J.js | AI (source-diff): Standard Vite-minified Vue3 bundle; readable imports from feedmepos org packages. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-DyiwvQnC.js | AI (source-diff): Main bundle with dayjs/pinia/Firebase; standard Vite minification. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-DPAxkce6.js | AI (source-diff): SheetJS and Vue component; no dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-DPAxkce6.js | AI (source-diff): Minified Vue component bundle including SheetJS xlsx; legitimate build output. | ai | |
| source-diff | net-exec-file:dist/App-Bt5lFavE.js | AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith CJS wrapper pattern. | ai | |
| source-diff | obfuscated-file:dist/App-Bt5lFavE.js | AI (source-diff): Minified Vue3 app bundle with Firebase/flagsmith; no malicious payload. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large bundle count is expected for a micro-frontend with many Vue components and bundled deps. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-DojmxFzq.js | AI (source-diff): Standard Vite minified asset bundle. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-OZZMb1gD.js | AI (source-diff): jszip minified library bundle; expected artifact. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-Cnq9QAeQ.js | AI (source-diff): Minified Vue component; CI env vars baked in are a build hygiene issue, not malware. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-IHmRgZTC.js | AI (source-diff): Firebase SDK network calls; commonjs interop dynamic execution is standard bundler pattern. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-IHmRgZTC.js | AI (source-diff): Main bundle with Firebase/pinia/dayjs; standard Vite minification. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-hEPchEwW.js | AI (source-diff): xlsx.js bundled library; network+exec pattern is false positive for this build artifact. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-hEPchEwW.js | AI (source-diff): Minified Vue component bundle including xlsx.js; standard build output. | ai | |
| source-diff | net-exec-file:dist/App-DqpxV0zp.js | AI (source-diff): Network calls are Firebase SDK; dynamic execution is flagsmith/commonjs interop pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/App-DqpxV0zp.js | AI (source-diff): Standard Vite minified output; samples show Vue/Firebase/flagsmith bundle, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/app-BSpY6Pgy.js | AI (source-diff): Standard Vite minified output for feedmepos Vue micro-frontend; consistent across versions. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-01qpukRE.js | AI (source-diff): Standard Vite minified Vue component bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-CVjWw9he.js | AI (source-diff): Standard Vite minified asset bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-rmsdV9dK.js | AI (source-diff): Standard Vite minified asset bundle. | ai | |
| source-diff | net-exec-file:dist/jszip.min-OZZMb1gD.js | AI (source-diff): jszip is a legitimate compression library; false positive for net-exec rule. | ai | |
| source-diff | obfuscated-file:dist/app-BU6wILmn.js | AI (source-diff): Standard Vite minified bundle output for this org's micro-frontend; not intentional obfuscation. | ai | |
| source-diff | obfuscated-file:dist/RuleView.vue_vue_type_script_setup_true_lang-DaCVUn1i.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/assets/override-menu-CASoFjhZ.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/assets/menu-export-CpcyYnR-.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/assets/linked-status-DTIHdzDw.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| source-diff | net-exec-file:dist/jszip.min-DlpCmtaR.js | AI (source-diff): jszip is a well-known library; no malicious pattern. | ai | |
| source-diff | obfuscated-file:dist/jszip.min-DlpCmtaR.js | AI (source-diff): jszip minified library bundled via Vite. | ai | |
| source-diff | obfuscated-file:dist/InventoryBinding.vue_vue_type_script_setup_true_lang-DzzwwdA_.js | AI (source-diff): Standard Vite bundle; leaked CI env vars are a hygiene issue, not malware. | ai | |
| source-diff | net-exec-file:dist/index.vue_vue_type_script_setup_true_lang-DSZsSghE.js | AI (source-diff): Firebase SDK + dayjs bundled; no malicious pattern. | ai | |
| source-diff | obfuscated-file:dist/index.vue_vue_type_script_setup_true_lang-DSZsSghE.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| source-diff | net-exec-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-Dpx4meDa.js | AI (source-diff): xlsx library bundled via Vite; no malicious network/exec pattern. | ai | |
| source-diff | obfuscated-file:dist/ImportProductDialog.vue_vue_type_script_setup_true_lang-Dpx4meDa.js | AI (source-diff): Standard Vite minified bundle; xlsx library bundled inline. | ai | |
| source-diff | net-exec-file:dist/App-C9b4SjED.js | AI (source-diff): Network calls are Firebase SDK; dynamic code is flagsmith feature-flag SDK bundled via Vite. | ai | |
| source-diff | obfuscated-file:dist/App-C9b4SjED.js | AI (source-diff): Standard Vite minified bundle output. | ai | |
| phantom-deps | phantom-dep:change-case | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:dotenv-cli | AI (phantom-deps): CLI tool used in scripts; not imported in source. | ai | |
| phantom-deps | phantom-dep:vue-i18n | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:firebase | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:i18next | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:exceljs | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:canvas | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:jszip | AI (phantom-deps): Same monorepo MFE pattern; not a real missing import. | ai | |
| phantom-deps | phantom-dep:@feedmepos/zod-entity | AI (phantom-deps): Internal org package; MFE federation boundary. | ai | |
| phantom-deps | phantom-dep:@types/dinero.js | AI (phantom-deps): Type-only package; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:vite-svg-loader | AI (phantom-deps): Build-time plugin; not imported in runtime source. | ai | |
| phantom-deps | phantom-dep:@feedmepos/auth | AI (phantom-deps): Internal org package; MFE federation boundary explains phantom detection. | ai | |
| phantom-deps | phantom-dep:vue3-carousel | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:vuedraggable | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:vue3-lottie | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Large monorepo MFE; phantom deps are expected due to shared module federation boundaries. | ai | |
| phantom-deps | phantom-dep:i18next-vue | AI (phantom-deps): Same monorepo MFE pattern. | ai | |
| phantom-deps | phantom-dep:file-saver | AI (phantom-deps): Same monorepo MFE pattern. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 0.32.59 | 42 / 23 | |
| 0.32.58 | 42 / 23 | |
| 0.32.52 | 42 / 23 | |
| 0.32.45 | 41 / 23 | |
| 0.32.43 | 41 / 23 | |
| 0.32.41 | 40 / 23 | |
| 0.32.39 | 40 / 23 | |
| 0.32.37 | 40 / 23 | |
| 0.32.36 | 40 / 23 | |
| 0.32.34 | 40 / 23 | |
| 0.32.33 | 40 / 23 | |
| 0.32.31 | 40 / 23 | |
| 0.32.29 | 40 / 23 | |
| 0.32.27 | 40 / 23 | |
| 0.32.26 | 40 / 23 | |
| 0.32.25 | 40 / 23 | |
| 0.32.24 | 40 / 23 | |
| 0.32.22 | 40 / 23 | |
| 0.32.8 | 40 / 24 | |
| 0.31.74 | 39 / 24 | |
| 0.31.59 | 39 / 24 |
v0.32.59
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.58
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.45
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.32.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.74
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.31.59
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.