← Home

@lit-protocol/crypto

3
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

glitch003adarsh-kumar28websaamhwrdtmfamuramaximushaximusspacesailorawisniew

Keywords

library

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ajv AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:depd AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:util AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:bech32 AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@lit-protocol/logger AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. ai
phantom-deps phantom-dep:@ethersproject/contracts AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@ethersproject/providers AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@lit-protocol/accs-schemas AI (phantom-deps): Same-org monorepo dep; stable false positive for this package. ai
phantom-deps phantom-dep:@ethersproject/abstract-provider AI (phantom-deps): Monorepo transitive dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@t3-oss/env-core AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:@openagenda/verror AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:@typechain/ethers-v6 AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is standard crypto key parsing in a BLS encryption library; not obfuscation. ai
phantom-deps phantom-dep:@lit-protocol/contracts AI (phantom-deps): Same-org monorepo dependency; expected pattern for Lit Protocol packages. ai
phantom-deps phantom-dep:@lit-protocol/access-control-conditions-schemas AI (phantom-deps): Same-org monorepo dependency; expected pattern for Lit Protocol packages. ai
phantom-deps phantom-dep:zod-validation-error AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding of ciphertext is expected in a crypto library's decrypt function. ai
typosquat typosquat.levenshtein:bcrypt AI (typosquat): Scoped package @lit-protocol/crypto is not a typosquat of bcrypt; different namespace and purpose. ai
phantom-deps phantom-dep:pako AI (phantom-deps): Monorepo shared dependency; declared at package level but used elsewhere in the SDK. ai
phantom-deps phantom-dep:siwe AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:ethers AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:typechain AI (phantom-deps): Monorepo shared dependency pattern in Lit Protocol JS SDK. ai
phantom-deps phantom-dep:@jest/globals AI (phantom-deps): Test framework dependency; loaded by convention, not direct import. ai

Versions (showing 3 of 3)

Version Deps Published
8.1.0 23 / 0
8.0.0 10 / 0
7.4.0 21 / 0

v8.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v8.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.