← Home

@kb-labs/studio-app

KB Labs Studio application

71
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

k.baranov

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/main.ccfa9d7c.js AI (source-diff): Bundled frontend app naturally contains fetch + eval-like patterns from deps; no concrete malicious behavior. ai
source-diff obfuscated-file:dist/main.ccfa9d7c.js AI (source-diff): Standard webpack/rspack minified bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/main.5ab9b765.js AI (source-diff): Webpack-bundled frontend app code, not true obfuscation. ai
source-diff net-exec-file:dist/main.5ab9b765.js AI (source-diff): Pattern match on bundled build output, not a dropper. ai
source-diff net-exec-file:dist/main.6d74fbe7.js AI (source-diff): Bundled frontend app code; network+eval patterns are from UI libs, not a dropper. ai
source-diff obfuscated-file:dist/main.6d74fbe7.js AI (source-diff): Webpack/rspack bundle of antd+UI deps, long lines are minification not obfuscation. ai
source-diff net-exec-file:dist/main.c282c309.js AI (source-diff): Pattern hit on large legit bundle (antd/rspack app), no dropper behavior shown. ai
source-diff obfuscated-file:dist/main.c282c309.js AI (source-diff): Webpack-bundled minified frontend code, not true obfuscation. ai
source-diff net-exec-file:dist/main.9bcc599c.js AI (source-diff): Generic pattern match on bundled SPA code, no fetched/executed payload found. ai
source-diff obfuscated-file:dist/main.9bcc599c.js AI (source-diff): Webpack-bundled frontend app output, not true obfuscation. ai
source-diff obfuscated-file:dist/main.98f0cac0.js AI (source-diff): Bundled webpack/rspack build output, not true obfuscation. ai
source-diff net-exec-file:dist/main.98f0cac0.js AI (source-diff): False positive on bundled frontend app code, no malicious behavior in sample. ai
source-diff obfuscated-file:dist/main.8ce0f6be.js AI (source-diff): Webpack/rspack bundled output, not true obfuscation (sample is standard antd color utils). ai
source-diff net-exec-file:dist/main.8ce0f6be.js AI (source-diff): Bundled frontend app code; no exfil/dropper behavior in sample. ai
source-diff obfuscated-file:dist/main.e2dd3ec0.js AI (source-diff): Webpack/rspack bundle output (antd theming code visible), not true obfuscation. ai
source-diff net-exec-file:dist/main.e2dd3ec0.js AI (source-diff): Bundled frontend app code; no concrete malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/main.90e4945f.js AI (source-diff): Bundled webpack/rspack output for a large React/antd app, not obfuscation. ai
source-diff net-exec-file:dist/main.90e4945f.js AI (source-diff): Bundled frontend chunk; network+eval patterns are from bundled libs, not malicious code. ai
source-diff obfuscated-file:dist/main.20db6ed1.js AI (source-diff): Webpack bundle of antd/react app; long minified lines, not true obfuscation. ai
source-diff net-exec-file:dist/main.20db6ed1.js AI (source-diff): Bundled frontend app naturally contains fetch + eval-like patterns from deps; no malicious target found. ai
source-diff net-exec-file:dist/main.e845eb60.js AI (source-diff): Bundled frontend app code, net+exec pattern from normal libs, no malicious behavior. ai
source-diff obfuscated-file:dist/main.e845eb60.js AI (source-diff): Webpack/rspack bundle of antd UI code, not true obfuscation. ai
source-diff obfuscated-file:dist/main.c46233f9.js AI (source-diff): Webpack-minified antd/react bundle, not true obfuscation — confirmed via sample. ai
source-diff net-exec-file:dist/main.c46233f9.js AI (source-diff): Bundled frontend app code, no fetched-binary/dropper behavior evident. ai
source-diff net-exec-file:dist/main.64272114.js AI (source-diff): Bundled frontend app code, not a dropper/loader. ai
source-diff obfuscated-file:dist/main.64272114.js AI (source-diff): Bundled webpack output (antd/rc-util code), not true obfuscation. ai
source-diff net-exec-file:dist/main.21c70340.js AI (source-diff): Bundled UI code (antd colors etc.), no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/main.21c70340.js AI (source-diff): Webpack-bundled frontend app output, not true obfuscation (no _0x/eval-atob patterns). ai
source-diff obfuscated-file:dist/main.37c37ea4.js AI (source-diff): Webpack/rspack bundle output, not true obfuscation; sample shows plain minified color utils. ai
source-diff net-exec-file:dist/main.37c37ea4.js AI (source-diff): Same bundled dist file, false positive from minified code density, not a dropper. ai
source-diff net-exec-file:dist/main.98dc4449.js AI (source-diff): Minified frontend bundle; network+eval patterns are normal in UI framework code. ai
source-diff obfuscated-file:dist/main.98dc4449.js AI (source-diff): Bundled webpack/rspack build output, not true obfuscation. ai
source-diff obfuscated-file:dist/main.be6a405e.js AI (source-diff): Webpack-bundled frontend chunk (antd/react-query), not true obfuscation. ai
source-diff net-exec-file:dist/main.be6a405e.js AI (source-diff): Bundled app code, not a dropper; matches package's React/antd stack. ai
source-diff net-exec-file:dist/main.231198dd.js AI (source-diff): Same bundled frontend file; network+eval patterns from bundler runtime, not a dropper. ai
source-diff obfuscated-file:dist/main.231198dd.js AI (source-diff): Rspack/webpack bundle output (antd/module-federation code visible), not true obfuscation. ai
source-diff obfuscated-file:dist/main.f0e7ecfd.js AI (source-diff): Webpack-bundled minified output, not true obfuscation; sample shows benign color utils. ai
source-diff net-exec-file:dist/main.f0e7ecfd.js AI (source-diff): Bundled frontend app code, pattern-matches on minified bundle not real net+exec. ai
source-diff obfuscated-file:dist/main.0d3d4b7a.js AI (source-diff): Bundled webpack/rspack output (antd theme code), not true obfuscation. ai
source-diff net-exec-file:dist/main.0d3d4b7a.js AI (source-diff): Bundled minified frontend code, no fetched-binary or credential-exfil behavior observed. ai
source-diff obfuscated-file:dist/main.563fdfce.js AI (source-diff): Standard webpack/rspack minified bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/main.563fdfce.js AI (source-diff): Bundled frontend app code; sample shows antd color utils, not a dropper. ai
source-diff obfuscated-file:dist/main.093308e3.js AI (source-diff): Webpack/rspack bundle of antd/react UI code, not obfuscation. ai
source-diff net-exec-file:dist/main.093308e3.js AI (source-diff): Bundled frontend app code, no concrete exfil/exec behavior found. ai
source-diff obfuscated-file:dist/main.f8efdc05.js AI (source-diff): Minified rspack/webpack bundle output, not true obfuscation; sample shows standard antd utility code. ai
source-diff net-exec-file:dist/main.f8efdc05.js AI (source-diff): Bundled frontend app code, not a dropper; pattern-matches on minified network/eval usage in vendored libs. ai
source-diff obfuscated-file:dist/main.0f9bfdbe.js AI (source-diff): Webpack-bundled frontend output, not true obfuscation. ai
source-diff net-exec-file:dist/main.0f9bfdbe.js AI (source-diff): Bundled React/antd app code, no evidence of dropper behavior. ai
source-diff net-exec-file:dist/main.73bbb774.js AI (source-diff): Bundled frontend app code (antd/react), no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/main.73bbb774.js AI (source-diff): Minified webpack/rspack bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/main.a1cfecb6.js AI (source-diff): Same bundled file; pattern-match on minified code, no actual network+exec malicious behavior shown. ai
source-diff obfuscated-file:dist/main.a1cfecb6.js AI (source-diff): Bundled antd/rspack output, not true obfuscation; sample shows standard minified color utility code. ai
source-diff net-exec-file:dist/main.55d1b43e.js AI (source-diff): Bundled frontend app code, network calls are normal app fetch/router logic, not a dropper. ai
source-diff obfuscated-file:dist/main.55d1b43e.js AI (source-diff): Bundled rspack/webpack output (antd/module-federation), not true obfuscation. ai
source-diff obfuscated-file:dist/main.dbb7476c.js AI (source-diff): Webpack/rspack bundle output (visible module banner, antd code), not true obfuscation. ai
source-diff net-exec-file:dist/main.dbb7476c.js AI (source-diff): Bundled frontend app code; network+eval patterns are standard bundler/runtime artifacts. ai
source-diff obfuscated-file:dist/main.d1c607ff.js AI (source-diff): Bundled rspack/webpack output, not true obfuscation — sample is minified antd color utils. ai
source-diff net-exec-file:dist/main.d1c607ff.js AI (source-diff): Same bundled file; network+exec pattern from bundled deps, no malicious behavior shown. ai
source-diff net-exec-file:dist/main.e975c83a.js AI (source-diff): Bundled frontend chunk; network+eval patterns are bundler artifacts, not a dropper. ai
source-diff obfuscated-file:dist/main.e975c83a.js AI (source-diff): Webpack/rspack bundle output (antd chunk), not true obfuscation. ai
source-diff net-exec-file:dist/main.1d68e922.js AI (source-diff): Bundled frontend chunk (antd utils), no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/main.1d68e922.js AI (source-diff): Webpack/rspack bundled output with sourcemap, not true obfuscation. ai
source-diff obfuscated-file:dist/main.548ebad3.js AI (source-diff): Standard webpack/rspack bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/main.548ebad3.js AI (source-diff): Bundled frontend app code, no actual dropper/loader behavior in sample. ai
source-diff net-exec-file:dist/main.5e93a5f0.js AI (source-diff): Bundled frontend code, sample shows standard UI library logic. ai
source-diff obfuscated-file:dist/main.5e93a5f0.js AI (source-diff): Webpack/rspack bundled output for a React app, not true obfuscation. ai
source-diff net-exec-file:dist/main.4c7b580a.js AI (source-diff): Minified bundle of a web app; fetch+eval patterns are framework runtime, no hostile target. ai
source-diff obfuscated-file:dist/main.4c7b580a.js AI (source-diff): Webpack/rspack bundled React app output, not obfuscation. ai
source-diff obfuscated-file:dist/main.226fbdb1.js AI (source-diff): Bundled webpack/rspack output (antd/react libs), not true obfuscation. ai
source-diff net-exec-file:dist/main.226fbdb1.js AI (source-diff): Frontend bundle chunk, no actual network+exec malicious behavior found. ai
source-diff obfuscated-file:dist/main.08802988.js AI (source-diff): Webpack/rspack bundle output, readable library code (antd color utils), not obfuscation. ai
source-diff net-exec-file:dist/main.08802988.js AI (source-diff): Bundled frontend app code; network+eval patterns are from bundled libs, not injected malware. ai
source-diff obfuscated-file:dist/main.68d6f0f6.js AI (source-diff): Webpack-bundled minified output (antd/theme code), not true obfuscation. ai
source-diff net-exec-file:dist/main.68d6f0f6.js AI (source-diff): Same bundled dist file; sample shows minified UI lib code, no exfil/exec behavior. ai
source-diff obfuscated-file:dist/main.1093c5b5.js AI (source-diff): Webpack/rspack bundle output (antd source visible), not true obfuscation. ai
source-diff net-exec-file:dist/main.1093c5b5.js AI (source-diff): Bundled frontend app code, no malicious network/exec payload found in sample. ai
source-diff net-exec-file:dist/main.6dfdb044.js AI (source-diff): Same bundled file; no concrete malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/main.6dfdb044.js AI (source-diff): Webpack-bundled build output (antd/rspack), not true obfuscation. ai
source-diff obfuscated-file:dist/main.b49e2680.js AI (source-diff): Webpack-bundled minified output (antd/react libs), not true obfuscation. ai
source-diff net-exec-file:dist/main.b49e2680.js AI (source-diff): Bundled frontend app code, no evidence of dropper/loader behavior. ai
source-diff obfuscated-file:dist/main.c1f3c947.js AI (source-diff): Bundled rspack/webpack output, not true obfuscation; sample shows normal antd color utils. ai
source-diff net-exec-file:dist/main.c1f3c947.js AI (source-diff): False positive on bundled frontend app code, no malicious network/exec behavior shown. ai
source-diff net-exec-file:dist/main.aa907bf2.js AI (source-diff): Bundled frontend app code, no hostile network/exec behavior observed. ai
source-diff obfuscated-file:dist/main.aa907bf2.js AI (source-diff): Webpack/rspack bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/main.f53bedf8.js AI (source-diff): Webpack-bundled antd/UI code, not true obfuscation. ai
source-diff net-exec-file:dist/main.f53bedf8.js AI (source-diff): False positive on minified bundle, no malicious payload found. ai
provenance missing-githead AI (provenance): Provenance direction unchanged; consistent with prior publishes for this package. ai
source-diff obfuscated-file:dist/main.86485e47.js AI (source-diff): Webpack/rspack bundle output (ant-design color utils visible), not true obfuscation. ai
source-diff net-exec-file:dist/main.86485e47.js AI (source-diff): Same bundled frontend chunk; no malicious network/exec behavior found in sample. ai
source-diff obfuscated-file:dist/main.ba55ee8f.js AI (source-diff): Webpack/rspack bundled frontend output, not true obfuscation. ai
source-diff net-exec-file:dist/main.ba55ee8f.js AI (source-diff): Bundled UI code (antd/reactflow), no evidence of dropper behavior. ai
source-diff net-exec-file:dist/main.4608c1a9.js AI (source-diff): Bundled frontend app code, sample shows legit UI lib code not a dropper. ai
source-diff obfuscated-file:dist/main.4608c1a9.js AI (source-diff): Webpack/rspack bundle output (antd/plots), not true obfuscation. ai
source-diff net-exec-file:dist/main.0c51fbec.js AI (source-diff): Bundled frontend app code, no evidence of dropper behavior. ai
source-diff obfuscated-file:dist/main.0c51fbec.js AI (source-diff): Webpack-bundled antd/react code, not true obfuscation. ai
source-diff obfuscated-file:dist/main.f818c531.js AI (source-diff): Bundled webpack/rspack output (antd/color utils), not true obfuscation. ai
source-diff net-exec-file:dist/main.f818c531.js AI (source-diff): Bundled frontend chunk; no concrete malicious network/exec behavior shown. ai
source-diff net-exec-file:dist/main.d0234626.js AI (source-diff): Bundled frontend app code, no evidence of dropper/exfil behavior. ai
source-diff obfuscated-file:dist/main.d0234626.js AI (source-diff): Webpack/rspack bundle output (antd color helpers), not true obfuscation. ai
source-diff net-exec-file:dist/main.18bf5235.js AI (source-diff): False positive from bundled network/UI libs (react-query, router) in minified build. ai
source-diff obfuscated-file:dist/main.18bf5235.js AI (source-diff): Bundled webpack/rspack output (antd theme utils), not true obfuscation. ai
source-diff net-exec-file:dist/main.d2d0fd74.js AI (source-diff): Bundled frontend app code; sample shows normal UI lib code, no dropper behavior. ai
source-diff obfuscated-file:dist/main.d2d0fd74.js AI (source-diff): Standard webpack/rspack minified bundle, not true obfuscation (no _0x/eval-atob patterns). ai
source-diff net-exec-file:dist/main.19aa8c57.js AI (source-diff): Network+exec pattern in a React SPA webpack bundle is expected; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/main.19aa8c57.js AI (source-diff): Standard webpack/rspack bundle output; sample shows antd color utilities, not obfuscation. ai
source-diff obfuscated-file:dist/main.ce22bb43.js AI (source-diff): Standard webpack bundle (Ant Design/React app); long lines are minified build output, not obfuscation. ai
source-diff net-exec-file:dist/main.ce22bb43.js AI (source-diff): Network calls and dynamic execution are expected in a React SPA webpack bundle; no hostile destination or dropper behavior. ai
source-diff obfuscated-file:dist/main.dba1b580.js AI (source-diff): Standard webpack bundle output; sample shows Ant Design color utilities, not obfuscation. ai
source-diff net-exec-file:dist/main.dba1b580.js AI (source-diff): Network+exec pattern in a frontend app bundle is expected; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/main.ab7bbf79.js AI (source-diff): Standard webpack/rspack bundle output for a React+antd app; not true obfuscation. ai
source-diff net-exec-file:dist/main.ab7bbf79.js AI (source-diff): Network+eval pattern is normal for webpack runtime module loading in a bundled SPA. ai
source-diff net-exec-file:dist/main.97660e1d.js AI (source-diff): Network calls and dynamic execution in a React SPA bundle are expected; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/main.97660e1d.js AI (source-diff): Standard webpack/rspack bundle output; long lines are minified React app code, not obfuscation. ai
source-diff net-exec-file:dist/main.c260f39a.js AI (source-diff): Network calls and dynamic requires are normal in a React SPA webpack bundle; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/main.c260f39a.js AI (source-diff): Standard webpack bundle output; __webpack_modules__ preamble confirms bundled artifact, not obfuscation. ai
source-diff net-exec-file:dist/main.65c9d0bc.js AI (source-diff): Network calls and dynamic execution are expected in a React SPA bundle; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/main.65c9d0bc.js AI (source-diff): Standard webpack/rspack bundle output for a React SPA; long lines are minified build artifacts, not obfuscation. ai
source-diff obfuscated-file:dist/main.c14f35f3.js AI (source-diff): Webpack bundle output with clear module structure; not obfuscation. ai
source-diff net-exec-file:dist/main.c14f35f3.js AI (source-diff): Bundled React app with network calls and dynamic imports; normal for this package. ai
source-diff net-exec-file:dist/main.ad42ef4a.js AI (source-diff): Webpack bundle naturally contains network calls and dynamic requires; no hostile payload. ai
source-diff obfuscated-file:dist/main.ad42ef4a.js AI (source-diff): Webpack bundle output (rspack build); not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Full app bundle shipped in dist/; size consistent with React+Ant Design app. ai
source-diff net-exec-file:dist/main.270b6745.js AI (source-diff): Network+exec pattern fires on webpack bundle; no concrete malicious behavior visible in sample. ai
source-diff obfuscated-file:dist/main.270b6745.js AI (source-diff): Standard webpack bundle output; sample shows Ant Design color palette logic, not true obfuscation. ai
phantom-deps phantom-dep:@kb-labs/core-contracts AI (phantom-deps): Same-org contract package; consistent with other @kb-labs/* phantom deps in this package. ai
phantom-deps phantom-dep:@kb-labs/studio-federation AI (phantom-deps): Same-org package; consistent pattern with other @kb-labs/* phantom deps. ai
phantom-deps phantom-dep:@kb-labs/studio-plugin-tools AI (phantom-deps): Same-org package; consistent pattern with other @kb-labs/* phantom deps. ai
source-diff net-exec-file:dist/main.9d8162c2.js AI (source-diff): Bundled React app with fetch calls and eval-like patterns from webpack runtime; not malicious. ai
source-diff obfuscated-file:dist/main.9d8162c2.js AI (source-diff): Webpack/rspack production bundle; minification is expected for this frontend app. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Well-known date library; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:lucide-react AI (phantom-deps): Well-known icon library; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:react-router-dom AI (phantom-deps): Legitimate routing dep; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:@ant-design/icons AI (phantom-deps): Legitimate Ant Design dep; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:@ant-design/plots AI (phantom-deps): Legitimate Ant Design dep; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:@kb-labs/studio-hooks AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/studio-ui-kit AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/studio-event-bus AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/studio-ui-core AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/studio-devtools AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Well-known utility; phantom-dep heuristic false positive for this bundled app package. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Declared runtime dep in a UI app; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/rest-api-contracts AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/quality-contracts AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/react-grid-layout AI (phantom-deps): Type definitions; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/agent-contracts AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@kb-labs/qa-contracts AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@ant-design/charts AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:react-grid-layout AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:react-resizable AI (phantom-deps): Peer dep of react-grid-layout; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. ai
semgrep semgrep:env-bulk-read AI (semgrep): Build config pattern: only forwards KB_-prefixed env vars into the bundle, not a credential leak. ai
phantom-deps phantom-dep:@kb-labs/release-manager-contracts AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled app ships compiled output; peer deps declared but not directly imported is expected. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Same as react — bundled app pattern. ai
phantom-deps phantom-dep:antd AI (phantom-deps): Bundled app; antd used in compiled output, not directly imported in analyzed entry. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled app pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@tanstack/react-query-devtools AI (phantom-deps): Bundled app pattern; stable false positive. ai
phantom-deps phantom-dep:@tanstack/react-query AI (phantom-deps): Bundled app pattern; stable false positive. ai
phantom-deps phantom-dep:zustand AI (phantom-deps): Bundled app pattern; stable false positive. ai
phantom-deps phantom-dep:reactflow AI (phantom-deps): Bundled app pattern; stable false positive. ai
phantom-deps phantom-dep:@kb-labs/workflow-contracts AI (phantom-deps): Same-org monorepo dep; bundled app pattern. ai
phantom-deps phantom-dep:@kb-labs/studio-data-client AI (phantom-deps): Same-org monorepo dep; bundled app pattern. ai

Versions (showing 71 of 71)

Version Deps Published
2.96.0 35 / 23
2.94.0 34 / 19
2.93.0 34 / 19
2.89.0 34 / 19
2.88.0 34 / 19
2.87.0 34 / 19
2.82.0 34 / 19
2.81.0 34 / 19
2.80.0 34 / 19
2.79.0 34 / 19
2.78.0 34 / 19
2.77.0 34 / 19
2.75.0 34 / 19
2.74.0 34 / 19
2.73.0 34 / 19
2.72.0 34 / 19
2.69.0 34 / 19
2.68.0 34 / 19
2.67.0 34 / 19
2.66.0 34 / 19
2.65.0 34 / 19
2.64.0 34 / 19
2.63.0 34 / 19
2.62.0 34 / 19
2.61.0 34 / 19
2.60.0 34 / 19
2.59.0 34 / 19
2.58.0 34 / 19
2.57.0 34 / 19
2.56.0 34 / 19
2.55.0 34 / 19
2.54.0 34 / 19
2.53.0 34 / 19
2.47.0 34 / 19
2.46.0 34 / 19
2.45.0 34 / 19
2.44.0 34 / 19
2.43.0 34 / 19
2.42.0 34 / 19
2.41.0 34 / 19
2.40.0 34 / 19
2.39.0 34 / 19
2.38.0 34 / 19
2.37.0 34 / 19
2.36.0 34 / 19
2.35.0 34 / 19
2.34.0 34 / 19
2.33.0 34 / 19
2.32.0 34 / 19
2.31.0 34 / 19
2.30.0 34 / 19
2.29.0 34 / 19
2.28.0 34 / 19
2.25.0 34 / 19
2.23.0 34 / 19
2.22.0 34 / 19
2.20.0 34 / 19
2.19.0 34 / 19
2.18.0 34 / 19
2.17.0 34 / 19
2.16.0 34 / 19
2.15.0 34 / 19
2.14.0 34 / 19
2.13.0 34 / 19
2.12.0 34 / 19
2.11.0 34 / 19
2.10.0 34 / 19
2.9.0 34 / 19
2.8.0 34 / 19
0.7.0 34 / 18
0.6.0 34 / 18

v2.96.0

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: k.baranov.

HIGH New obfuscated file: dist/main.270b6745.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/main.270b6745.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.61.0

4 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: k.baranov.

HIGH New obfuscated file: dist/main.68d6f0f6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/main.68d6f0f6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.