@fluid-app/portal-sdk
SDK for building custom Fluid portals
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/FluidProvider-P_MBgI-c.cjs | AI (source-diff): Bundled build output (long require-chain lines), not true obfuscation; code is plain widget logic. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CsZsCnnX.cjs | AI (source-diff): Bundled build output, sample shows normal React hook/component code. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-P_MBgI-c.cjs | AI (source-diff): Bundler chunk referencing app API contexts, no dropper/loader behavior found. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-nng7xcyK.cjs | AI (source-diff): Bundled build output for new Messaging feature, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-T7GATgZf.cjs | AI (source-diff): Bundled require-chain of internal chunks, no fetched/executed remote payload. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-T7GATgZf.cjs | AI (source-diff): Minified bundler output (tsdown/rollup chunk), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-B-6PKi1Z.mjs | AI (source-diff): Bundled ESM chunk output, minified imports not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CszrlhFR.mjs | AI (source-diff): Bundled ESM chunk output for messaging UI, not obfuscation. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): Bundled build output (tsdown/rollup chunks), not true obfuscation. | ai | |
| email-domain | unclaimed-email:blowmage.com | AI (email-domain): Hygiene issue on established SDK, not behavioral evidence of compromise. | ai | |
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Sample shows ordinary requires/bundled code, no fetch+exec payload. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-D_jry4m5.cjs | AI (source-diff): Network+exec pattern is normal React SDK code (fetch/query hooks), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-JZNWyshx.cjs | AI (source-diff): Bundled build output, matches package widget structure. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-D_jry4m5.cjs | AI (source-diff): Minified bundler output (tsdown/esbuild require-chain), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-fziXNUL8.cjs | AI (source-diff): Bundled module graph; no actual network+exec malicious payload in sample. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-vGbrEL0w.mjs | AI (source-diff): Bundled ESM output, same pattern as sibling chunks. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Bps-x5Rz.mjs | AI (source-diff): Bundled ESM output with long import lists, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-portal-card-add-3ds-flow-Cr6rGltD.cjs | AI (source-diff): Bundled build output, standard chunked requires. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-Ch82wmzw.cjs | AI (source-diff): Bundled build output, standard chunked requires. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-fziXNUL8.cjs | AI (source-diff): Bundled build output (tsdown/rollup chunk requires), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BqGHECjV.cjs | AI (source-diff): Bundler chunk with require+network APIs used for app data fetching, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/use-portal-card-add-3ds-flow-BLmdLBnY.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/ShareablesScreen-BTa8CeWo.cjs | AI (source-diff): Bundler chunk, no malicious network/exec behavior found in sample. | ai | |
| source-diff | obfuscated-file:dist/ShareablesScreen-BTa8CeWo.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-BGtnLjT4.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BqGHECjV.cjs | AI (source-diff): Bundled build output, not obfuscation; legible module requires and component code. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-d2xkELCP.cjs | AI (source-diff): require chain is bundler chunk loading, not dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-d4E-pPU2.mjs | AI (source-diff): Bundled ESM build output. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Vox9-7PR.mjs | AI (source-diff): Bundled ESM build output. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-zlASVP2j.cjs | AI (source-diff): Bundled build output, matches known SDK component structure. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-d2xkELCP.cjs | AI (source-diff): Bundled build output (tsdown/vite chunks), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/ShareablesScreen-CxuFvClS.cjs | AI (source-diff): Bundled app code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-DcJ43dZs.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-NemU6JGa.cjs | AI (source-diff): Standard fetch/query code in bundled chunk, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-NemU6JGa.cjs | AI (source-diff): Bundled build output (tsdown/rollup chunk), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ShareablesScreen-CxuFvClS.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-portal-card-add-3ds-flow-BojVWS0M.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| dependencies | unvetted-dep:@fluid-app/portal-preview | AI (dependencies): First-party monorepo sibling dependency, same publisher/org. | ai | |
| dependencies | unvetted-dep:@fluid-app/widget-runtime | AI (dependencies): First-party sibling package within same @fluid-app monorepo. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party siblings, not external packages. | ai | |
| dependencies | unvetted-dep:@fluid-app/ui-components | AI (dependencies): First-party sibling package within same @fluid-app monorepo. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-I5DPaIq7.cjs | AI (source-diff): Bundled build output (require chain to sibling chunks), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-D0O8xW76.cjs | AI (source-diff): Bundled build output for messaging widget, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-I5DPaIq7.cjs | AI (source-diff): Bundled SDK code; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-CoSgK0jL.cjs | AI (source-diff): Bundled UI SDK chunk requiring sibling first-party modules, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-CoSgK0jL.cjs | AI (source-diff): Bundled tsdown output with long lines, not true obfuscation; matches internal SDK module graph. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BLri8EGR.cjs | AI (source-diff): Standard bundled require/fetch calls, no hostile network+exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BLri8EGR.cjs | AI (source-diff): Bundled build output (tsdown/esbuild chunking), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CLcsshRX.cjs | AI (source-diff): Bundled build output, matches package's widget architecture. | ai | |
| dependencies | unvetted-dep:@fluid-app/messaging-ui | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Utility used via config/build tooling, common false positive. | ai | |
| dependencies | unvetted-dep:@fluid-app/messaging-api-client | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| dependencies | unvetted-dep:@fluid-app/portal-widgets | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| dependencies | unvetted-dep:@fluid-app/messaging-core | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| dependencies | unvetted-dep:@fluid-app/auth | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| dependencies | unvetted-dep:@fluid-app/portal-core | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| phantom-deps | phantom-dep:class-variance-authority | AI (phantom-deps): Utility used via config/build tooling, common false positive. | ai | |
| phantom-deps | phantom-dep:@radix-ui/react-slot | AI (phantom-deps): UI lib referenced indirectly, common false positive. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Utility used via config/build tooling, common false positive. | ai | |
| phantom-deps | phantom-dep:qrcode.react | AI (phantom-deps): UI lib referenced indirectly, common false positive. | ai | |
| phantom-deps | phantom-dep:recharts | AI (phantom-deps): UI lib referenced indirectly, common false positive. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-0sOzJmJn.cjs | AI (source-diff): Bundled require-graph of internal widgets, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-0sOzJmJn.cjs | AI (source-diff): Bundled SDK code, no evidence of loader/dropper behavior. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-Cdz1kU5H.cjs | AI (source-diff): Bundler chunk requiring sibling modules; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Cdz1kU5H.cjs | AI (source-diff): Bundled build output aggregating internal widget chunks, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-lgII8Oel.cjs | AI (source-diff): Bundled/minified require-graph output from tsdown build, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-lgII8Oel.cjs | AI (source-diff): Widget SDK bundle with normal fetch/dynamic-import, no exfil behavior shown. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BYY876dq.cjs | AI (source-diff): Bundled SDK code aggregating widget modules, no fetched-binary exec observed. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BYY876dq.cjs | AI (source-diff): Bundled tsdown output (require-chunk pattern), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-IFbNov8P.cjs | AI (source-diff): Bundled tsdown output with long lines, not real obfuscation; no malicious payload in sample. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-IFbNov8P.cjs | AI (source-diff): False positive: sample is local require() chain of bundled chunks, not network+exec dropper. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BIeO1i4r.cjs | AI (source-diff): Bundled SDK network client code, not a dropper/loader pattern. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BIeO1i4r.cjs | AI (source-diff): Bundled require-graph output, not true obfuscation (no _0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/FluidProvider-DTdECylI.cjs | AI (source-diff): Bundle aggregates internal widget modules; no fetched/executed payload. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-DTdECylI.cjs | AI (source-diff): Bundled build output (tsdown/rollup), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-DXvgVTmO.cjs | AI (source-diff): False positive on bundled widget-loading code, no fetched/executed payload observed. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-DXvgVTmO.cjs | AI (source-diff): Bundled require-chain aggregator, not true obfuscation; long lines are build output. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-CMfpLju8.cjs | AI (source-diff): Minified bundler output (tsdown/esbuild), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CvyQL50O.cjs | AI (source-diff): Minified bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-CMfpLju8.cjs | AI (source-diff): Bundled require chain of internal widgets, no dropper/loader behavior. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-CZan7yJ3.cjs | AI (source-diff): Bundled component chunk; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-CZan7yJ3.cjs | AI (source-diff): Bundled build chunk (tsdown/rollup require-graph), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Bc-ejPL4.cjs | AI (source-diff): Bundled build output (tsdown), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-k9i2ahoH.mjs | AI (source-diff): Bundled ESM build output. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BeoE50u-.mjs | AI (source-diff): Bundled ESM build output with long import lines. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-D_6wWdwM.cjs | AI (source-diff): Bundled build output, minified chunk requires. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-Bc-ejPL4.cjs | AI (source-diff): Bundle mixes unrelated require+fetch calls across the file, not a dropper. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BFU7ermL.cjs | AI (source-diff): Bundled SDK code; no fetched-binary or exfil behavior present. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-D_wVko-i.cjs | AI (source-diff): Bundled build output for messaging UI module, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BFU7ermL.cjs | AI (source-diff): Bundled tsdown output with long require chains, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-DeYSVcMd.cjs | AI (source-diff): Minified bundler output, not true obfuscation; no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-Y4bOFCeb.cjs | AI (source-diff): Bundled SDK code; no evidence of malicious network/exec behavior beyond normal app bundle. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Y4bOFCeb.cjs | AI (source-diff): Bundled build output (tsdown/rollup chunks) with source maps, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-D9zBmiaG.mjs | AI (source-diff): Bundled ESM chunk, consistent with tsdown build output. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BFF-jYEi.mjs | AI (source-diff): Bundled ESM chunk with source map, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-DDvXMf79.cjs | AI (source-diff): Bundled build output, matches package's normal chunked dist layout. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-Ca_m3XxG.cjs | AI (source-diff): Sample shows only internal module requires, no fetched/executed remote code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from bundler chunk splitting in an actively developed monorepo SDK. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-xdkxwXU-.cjs | AI (source-diff): Bundled minified output, standard React/query imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Ca_m3XxG.cjs | AI (source-diff): Bundled minified output (tsdown/esbuild chunk), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-Dgy4onF4.cjs | AI (source-diff): Bundled SDK code using react-query/API clients per package purpose, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CCb05_Wj.mjs | AI (source-diff): Bundled ESM build output for messaging screen feature. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-DV227FL2.mjs | AI (source-diff): Bundled ESM build output, same provider module as cjs counterpart. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-C69BJ8Fz.cjs | AI (source-diff): Bundled build output, matches package's messaging UI feature. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-Dgy4onF4.cjs | AI (source-diff): Bundled build output (tsdown/esbuild chunk requires), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-D2ZXrmtu.cjs | AI (source-diff): False positive on bundled require calls, no evidence of exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/use-portal-card-add-3ds-flow-Ca7Fvofg.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-Dne7NwPj.cjs | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-D2ZXrmtu.cjs | AI (source-diff): Bundler-concatenated require graph, not true obfuscation; readable source. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CkXV8WHH.cjs | AI (source-diff): Standard tsdown/vite bundle output with readable source, comments, and named imports — not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-BaGLql5n.cjs | AI (source-diff): Standard tsdown bundle output with source maps; long lines are minified but not obfuscated — readable code visible in sample. | ai | |
| source-diff | obfuscated-file:dist/src-UnXevN9n.cjs | AI (source-diff): Standard tsdown/rollup CJS bundle with readable source regions and known deps; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-DgbNN4BF.cjs | AI (source-diff): Standard tsdown/rollup CJS bundle with readable source regions and known deps; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-DGxCCmVB.cjs | AI (source-diff): Standard Vite/tsdown bundle with readable widget imports; long lines are minified but not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-GLb5id9n.cjs | AI (source-diff): Same build artifact pattern; readable source with React/tanstack-query imports, not malicious obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-DGxCCmVB.cjs | AI (source-diff): Network calls and dynamic requires are part of the SDK's normal API client and widget loading pattern. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-8gH4_8Qn.cjs | AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-CBDJKNe2.mjs | AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-hXzE3QsO.mjs | AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-B3i7W5r6.cjs | AI (source-diff): Network calls and dynamic requires are normal React SDK bundle patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-B3i7W5r6.cjs | AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-DlRwCPg8.mjs | AI (source-diff): Standard Vite bundle output; sample shows readable React/ESM code, long lines are bundler artifacts. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-_-sdlwh0.cjs | AI (source-diff): Standard Vite bundle output; sample shows readable React code with normal imports, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-ClnTfJPR.mjs | AI (source-diff): Standard ESM bundle output for messaging screen; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-CiMgrTE0.cjs | AI (source-diff): Standard Vite/tsdown bundle output; long lines are minified but readable widget imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-B0nvkVRJ.cjs | AI (source-diff): Standard Vite/tsdown bundle output for messaging feature; not obfuscated. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-CiMgrTE0.cjs | AI (source-diff): Network calls and dynamic requires are expected in a portal SDK provider bundle; no dropper pattern visible. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BdjVFM6g.mjs | AI (source-diff): Standard ESM bundle output; long import lines are normal for bundled SDK. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BAg3B4eD.cjs | AI (source-diff): Network calls and dynamic requires are normal React SDK bundler patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CJ0Rj-M7.cjs | AI (source-diff): Standard bundled CJS output for MessagingScreen feature; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BAg3B4eD.cjs | AI (source-diff): Standard Vite/tsdown bundle output; long lines are minified but not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-0iAzXjtW.mjs | AI (source-diff): Standard bundled ESM output for MessagingScreen; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-C00Px_ej.mjs | AI (source-diff): Standard bundled ESM output; imports are named widget/provider modules consistent with SDK structure. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-BQjPCP_2.cjs | AI (source-diff): Sample shows standard CJS bundler re-export wrappers, not obfuscation; consistent with tsdown build output for this SDK. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-BQjPCP_2.cjs | AI (source-diff): Network calls and dynamic requires are part of the SDK's widget/API client architecture, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CZddjqma.mjs | AI (source-diff): Standard Vite/tsdown ESM bundle output; sample shows readable React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-D3S230Ba.cjs | AI (source-diff): Standard Vite/tsdown CJS bundle output; sample shows readable React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/FluidProvider-C9DPE1F0.cjs | AI (source-diff): Long lines are Vite/tsdown CJS bundle barrel requires, not obfuscation. Stable pattern for this build toolchain. | ai | |
| source-diff | net-exec-file:dist/FluidProvider-C9DPE1F0.cjs | AI (source-diff): Network calls and dynamic requires in a portal SDK bundle are expected; no dropper pattern visible in sample. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CwzSY_G8.mjs | AI (source-diff): Standard tsdown/Vite bundle output; samples show readable React code, not obfuscation. | ai | |
| phantom-deps | phantom-dep:use-sync-external-store | AI (phantom-deps): Bundled transitive dep; phantom-dep false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-2M2ETWXp.cjs | AI (source-diff): Standard tsdown/Vite bundle output; samples show readable React code, not obfuscation. | ai | |
| phantom-deps | phantom-dep:tw-animate-css | AI (phantom-deps): CSS-only package; not imported via JS but used via config/CSS — phantom-dep heuristic is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:embla-carousel-react | AI (phantom-deps): Carousel lib likely consumed via re-export or config; phantom-dep heuristic is a stable false positive for this SDK. | ai | |
| source-diff | obfuscated-file:dist/MessagingScreen-CCbgNRp1.cjs | AI (source-diff): Standard Vite/tsdown bundle output; long lines from minification, not obfuscation. Code is fully readable in sample. | ai |
Versions (showing 100 of 335)
| Version | Deps | Published |
|---|---|---|
| 0.1.445 | 12 / 63 | |
| 0.1.437 | 13 / 64 | |
| 0.1.426 | 10 / 65 | |
| 0.1.424 | 10 / 65 | |
| 0.1.423 | 10 / 65 | |
| 0.1.422 | 10 / 65 | |
| 0.1.416 | 10 / 65 | |
| 0.1.412 | 10 / 65 | |
| 0.1.411 | 10 / 65 | |
| 0.1.410 | 10 / 65 | |
| 0.1.404 | 10 / 65 | |
| 0.1.403 | 10 / 65 | |
| 0.1.401 | 10 / 65 | |
| 0.1.388 | 10 / 66 | |
| 0.1.382 | 10 / 66 | |
| 0.1.379 | 10 / 66 | |
| 0.1.376 | 10 / 66 | |
| 0.1.375 | 10 / 66 | |
| 0.1.360 | 10 / 68 | |
| 0.1.359 | 10 / 68 | |
| 0.1.358 | 10 / 68 | |
| 0.1.356 | 10 / 68 | |
| 0.1.355 | 10 / 68 | |
| 0.1.354 | 10 / 68 | |
| 0.1.353 | 10 / 68 | |
| 0.1.352 | 10 / 68 | |
| 0.1.349 | 10 / 67 | |
| 0.1.348 | 10 / 67 | |
| 0.1.347 | 10 / 67 | |
| 0.1.346 | 10 / 67 | |
| 0.1.345 | 10 / 67 | |
| 0.1.342 | 10 / 67 | |
| 0.1.341 | 10 / 67 | |
| 0.1.337 | 10 / 67 | |
| 0.1.335 | 10 / 67 | |
| 0.1.334 | 10 / 67 | |
| 0.1.333 | 10 / 67 | |
| 0.1.332 | 10 / 67 | |
| 0.1.330 | 10 / 67 | |
| 0.1.329 | 10 / 67 | |
| 0.1.327 | 10 / 67 | |
| 0.1.326 | 10 / 67 | |
| 0.1.325 | 10 / 67 | |
| 0.1.324 | 10 / 67 | |
| 0.1.323 | 10 / 67 | |
| 0.1.322 | 10 / 67 | |
| 0.1.321 | 10 / 67 | |
| 0.1.316 | 10 / 67 | |
| 0.1.315 | 10 / 67 | |
| 0.1.314 | 10 / 67 | |
| 0.1.313 | 10 / 67 | |
| 0.1.312 | 10 / 67 | |
| 0.1.311 | 10 / 67 | |
| 0.1.310 | 10 / 67 | |
| 0.1.309 | 10 / 67 | |
| 0.1.308 | 10 / 67 | |
| 0.1.307 | 10 / 67 | |
| 0.1.306 | 10 / 67 | |
| 0.1.305 | 10 / 67 | |
| 0.1.304 | 10 / 67 | |
| 0.1.303 | 10 / 67 | |
| 0.1.302 | 10 / 67 | |
| 0.1.301 | 10 / 67 | |
| 0.1.300 | 10 / 67 | |
| 0.1.299 | 10 / 67 | |
| 0.1.298 | 10 / 67 | |
| 0.1.297 | 10 / 67 | |
| 0.1.296 | 10 / 67 | |
| 0.1.295 | 10 / 67 | |
| 0.1.294 | 10 / 67 | |
| 0.1.293 | 10 / 67 | |
| 0.1.292 | 10 / 67 | |
| 0.1.291 | 10 / 67 | |
| 0.1.290 | 10 / 67 | |
| 0.1.289 | 10 / 67 | |
| 0.1.288 | 10 / 67 | |
| 0.1.287 | 10 / 67 | |
| 0.1.286 | 10 / 67 | |
| 0.1.285 | 10 / 67 | |
| 0.1.284 | 10 / 67 | |
| 0.1.281 | 10 / 67 | |
| 0.1.280 | 10 / 67 | |
| 0.1.274 | 10 / 67 | |
| 0.1.273 | 10 / 67 | |
| 0.1.270 | 10 / 67 | |
| 0.1.269 | 10 / 67 | |
| 0.1.268 | 10 / 67 | |
| 0.1.267 | 10 / 67 | |
| 0.1.266 | 10 / 67 | |
| 0.1.265 | 10 / 67 | |
| 0.1.264 | 10 / 67 | |
| 0.1.263 | 10 / 67 | |
| 0.1.262 | 10 / 67 | |
| 0.1.261 | 10 / 67 | |
| 0.1.260 | 10 / 67 | |
| 0.1.259 | 10 / 67 | |
| 0.1.258 | 10 / 67 | |
| 0.1.257 | 10 / 67 | |
| 0.1.256 | 10 / 67 | |
| 0.1.255 | 10 / 67 |
v0.1.445
2 findingsMaintainer email '[email protected]' uses domain 'blowmage.com' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.437
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.426
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.424
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.423
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.422
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.416
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.412
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.411
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.410
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.404
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.403
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.401
2 findingsThis version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.359
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.352
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.342
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.341
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.337
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.335
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.334
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.333
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.332
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.330
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.323
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.322
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.321
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.316
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.315
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.314
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.297
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.295
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.294
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.293
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.292
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.281
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.280
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.270
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.269
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.268
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.267
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.266
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.265
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.264
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.263
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.262
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.261
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.260
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.259
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.258
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.257
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.256
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.255
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.