← Home

@luxonis/visualizer-protobuf

27
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

luxonis-adminfilipprochdavidfencldzenda

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-BIIHWu1p.js AI (source-diff): Bundled vendor deps (lezer, CodeMirror, react libs), not true obfuscation. ai
source-diff net-exec-file:dist/index-Dz5WEhSI.js AI (source-diff): Same bundled build artifact, no fetched/executed payload. ai
source-diff net-exec-file:dist/index-BIIHWu1p.js AI (source-diff): Bundled comlink/protobuf/websocket code inherent to visualizer, not a dropper. ai
source-diff obfuscated-file:dist/decodeImage-CknL-EpW.js AI (source-diff): Bundled lodash/codemirror chunk, not true obfuscation. ai
source-diff net-exec-file:dist/index-EUVKEGOd.js AI (source-diff): Pattern match inside bundled build output, no dropper behavior. ai
source-diff net-exec-file:dist/index-DJU7lf9I.js AI (source-diff): Pattern match inside bundled build output, no dropper behavior. ai
source-diff net-exec-file:dist/decodeImage-CknL-EpW.js AI (source-diff): Pattern match inside bundled build output, no dropper behavior. ai
source-diff obfuscated-file:dist/index-DgJK8CVA.js AI (source-diff): Bundled build output (rollup/vite chunk with third-party libs), not true obfuscation. ai
source-diff net-exec-file:dist/index-DgJK8CVA.js AI (source-diff): Bundled chunk combining protobuf/comlink libs; no dropper behavior found. ai
source-diff obfuscated-file:dist/index-8bTMarZg.js AI (source-diff): Bundled editor/language support chunk (lezer-generator), standard bundler output. ai
source-diff net-exec-file:dist/index-1D5S7eR3.js AI (source-diff): Bundled deps, no malicious network target identified. ai
source-diff net-exec-file:dist/index-BWUFvnnr.js AI (source-diff): Bundled protobuf/react code; no evidence of malicious exec/exfil. ai
source-diff obfuscated-file:dist/index-BWUFvnnr.js AI (source-diff): Standard rollup bundle chunk with many legit imports. ai
source-diff obfuscated-file:dist/index-4r5XO2hY.js AI (source-diff): lezer-generator bundled output, not obfuscation. ai
source-diff obfuscated-file:dist/index-1D5S7eR3.js AI (source-diff): Bundled React/UI code from rollup build, not obfuscated. ai
source-diff obfuscated-file:dist/index-ANY2H_o3.js AI (source-diff): Bundled lezer-generator parser output, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BG2Ave0p.js AI (source-diff): Bundled lezer-generator parser output, minified not obfuscated. ai
source-diff net-exec-file:dist/index-5b5DlnDp.js AI (source-diff): Minified bundle triggers net+exec heuristic; no malicious behavior found. ai
source-diff obfuscated-file:dist/index-5b5DlnDp.js AI (source-diff): Bundled rollup/vite chunk (React/lezer/protobuf), not true obfuscation. ai
source-diff obfuscated-file:dist/index-Bxmz2JGo.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/index-bekfXYhw.js AI (source-diff): lezer-generator output bundled by rollup, not obfuscation. ai
source-diff obfuscated-file:dist/index-C160LZiW.js AI (source-diff): lezer-generator bundled output. ai
source-diff obfuscated-file:dist/index-CEmQpnf1.js AI (source-diff): lezer-generator bundled output. ai
source-diff obfuscated-file:dist/index-CF1qeWCH.js AI (source-diff): lezer-generator bundled output. ai
source-diff net-exec-file:dist/index-Bxmz2JGo.js AI (source-diff): Minified bundle triggers net+exec heuristic; no malicious behavior found. ai
source-diff obfuscated-file:dist/index-CKt938IX.js AI (source-diff): Bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-BJj3DCnA.js AI (source-diff): Bundled build output (rollup), not true obfuscation. ai
source-diff net-exec-file:dist/index-BJj3DCnA.js AI (source-diff): Bundled app code with normal fetch/dynamic-import, not dropper malware. ai
source-diff net-exec-file:dist/index-CKt938IX.js AI (source-diff): Bundled app code with normal fetch/dynamic-import, not dropper malware. ai
source-diff obfuscated-file:dist/index-BsdHlfPa.js AI (source-diff): lezer-generator output, minified bundle. ai
source-diff obfuscated-file:dist/index-DDDjobHa.js AI (source-diff): Bundled vendor chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BNBWBozz.js AI (source-diff): Rollup-bundled vendor code, minified not obfuscated. ai
source-diff net-exec-file:dist/index-AY6RFcAW.js AI (source-diff): Bundled library chunk contains normal fetch/eval patterns from deps, no malicious behavior. ai
source-diff obfuscated-file:dist/index-AY6RFcAW.js AI (source-diff): Rollup-bundled vendor code (lodash/react/protobuf), not obfuscation. ai
source-diff net-exec-file:dist/index-BNBWBozz.js AI (source-diff): Bundled library chunk, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/index-B6CSn3bW.js AI (source-diff): lezer-generator output, minified bundle. ai
source-diff obfuscated-file:dist/index-CmXHlFr5.js AI (source-diff): lezer-generator output, minified bundle. ai
source-diff obfuscated-file:dist/index-Bf5zVcAc.js AI (source-diff): Bundled codemirror language module, not obfuscation. ai
source-diff obfuscated-file:dist/index-BG23zkos.js AI (source-diff): Bundled lezer-generator output, not obfuscation. ai
source-diff obfuscated-file:dist/index-Bl1gi-zh.js AI (source-diff): Bundled lezer-generator CSS module, not obfuscation. ai
source-diff obfuscated-file:dist/index-B4QJRCC8.js AI (source-diff): Bundled lezer parser/UI code, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BIOeAcXP.js AI (source-diff): Same bundled parser output pattern as sibling files. ai
source-diff obfuscated-file:dist/index-BimzNWm5.js AI (source-diff): Bundled lezer language support, minified build output. ai
source-diff obfuscated-file:dist/index-BFuISzq9.js AI (source-diff): Bundled lezer/codemirror language support, minified build output. ai
source-diff net-exec-file:dist/index-B_3PleIH.js AI (source-diff): Bundled visualizer UI code; no concrete malicious network target identified. ai
source-diff obfuscated-file:dist/index-B_3PleIH.js AI (source-diff): Bundled React/UI code, minified not obfuscated. ai
source-diff obfuscated-file:dist/index--95nXh6E.js AI (source-diff): Bundled lezer-generator parser output, not obfuscation. ai
source-diff obfuscated-file:dist/index-0eLSwhoo.js AI (source-diff): lezer-generator generated parser bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BO7SiaLV.js AI (source-diff): lezer-generator generated parser bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-B9Z4uArr.js AI (source-diff): Generated lezer parser bundle, not obfuscation. ai
source-diff obfuscated-file:dist/index-_apLu4SL.js AI (source-diff): Rollup bundle of app code (React/MUI), not obfuscation. ai
source-diff net-exec-file:dist/index-_apLu4SL.js AI (source-diff): Bundled app code, false positive on minified/network-capable app bundle. ai
source-diff obfuscated-file:dist/index-B_6J3epQ.js AI (source-diff): Generated lezer parser bundle, not obfuscation. ai
source-diff net-exec-file:dist/index-Be6EYnox.js AI (source-diff): Bundled code; network+eval pattern from standard libs, not malicious. ai
source-diff net-exec-file:dist/index-BlROWu-J.js AI (source-diff): Bundled React/UI code, not a dropper. ai
source-diff obfuscated-file:dist/index-BlROWu-J.js AI (source-diff): Bundled minified output. ai
source-diff obfuscated-file:dist/index-BEUjTghZ.js AI (source-diff): Bundled minified output. ai
source-diff obfuscated-file:dist/index-B-g3aWAt.js AI (source-diff): Bundled minified output (lezer parser generator). ai
source-diff obfuscated-file:dist/index-Be6EYnox.js AI (source-diff): Main bundled app entry, standard rollup output. ai
source-diff obfuscated-file:dist/index-Bi4nJb4U.js AI (source-diff): Main bundle output from rollup build, not obfuscation. ai
source-diff obfuscated-file:dist/index-BF6pGj6y.js AI (source-diff): React/rollup bundled output, not obfuscation. ai
source-diff net-exec-file:dist/index-BF6pGj6y.js AI (source-diff): Bundled app code, no concrete malicious network+exec behavior shown. ai
source-diff net-exec-file:dist/index-Bi4nJb4U.js AI (source-diff): Bundled protobuf/UI code; no dropper/loader pattern in sample. ai
source-diff obfuscated-file:dist/index-BsCcQbSo.js AI (source-diff): Bundled codemirror language module. ai
source-diff obfuscated-file:dist/index-BN1XXU26.js AI (source-diff): Bundled codemirror language module. ai
source-diff obfuscated-file:dist/index-BGnPWAxp.js AI (source-diff): Bundled lezer/codemirror language grammar, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-aCoqRfTl.js AI (source-diff): Rollup-bundled lezer/codemirror chunk, long lines are minification. ai
source-diff obfuscated-file:dist/index-B4osw0hO.js AI (source-diff): Bundled lezer parser chunk. ai
source-diff obfuscated-file:dist/index-B7AEFuPp.js AI (source-diff): Bundled lezer parser chunk. ai
source-diff obfuscated-file:dist/index-B8amzXr1.js AI (source-diff): Bundled React/mosaic vendor chunk, not obfuscation. ai
source-diff net-exec-file:dist/index-B8amzXr1.js AI (source-diff): Bundled vendor chunk false positive. ai
source-diff obfuscated-file:dist/index-BNRG4n8S.js AI (source-diff): Bundled codemirror/lezer chunk, minified build output not obfuscation. ai
source-diff net-exec-file:dist/index-BTrKy8v9.js AI (source-diff): Same bundled chunk; no malicious network+exec behavior evident. ai
source-diff obfuscated-file:dist/index-BTrKy8v9.js AI (source-diff): Bundled React/MUI/zustand chunk, standard bundler output. ai
source-diff net-exec-file:dist/index-Uxn2h85I.js AI (source-diff): Same bundled chunk pattern as above. ai
source-diff net-exec-file:dist/index-BP2oHfNr.js AI (source-diff): Comlink/websocket usage inherent to visualizer bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-BP2oHfNr.js AI (source-diff): Bundled rollup output, not true obfuscation; matches declared deps. ai
source-diff net-exec-file:dist/index-wxnOzmSh.js AI (source-diff): Bundled vendor libs; no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:dist/index-BArQYoU9.js AI (source-diff): Bundled lezer-generator/CodeMirror parser code, not true obfuscation. ai
source-diff obfuscated-file:dist/index-BLTVlMYq.js AI (source-diff): Bundled React/MUI vendor code from rollup build. ai
source-diff net-exec-file:dist/index-BLTVlMYq.js AI (source-diff): Bundled vendor libs; no concrete malicious network/exec behavior shown. ai
source-diff large-new-source-files AI (source-diff): Expected growth from bundling many editor/protobuf dependencies. ai
source-diff net-exec-file:dist/decodeImage-DseBx4N0.js AI (source-diff): Bundled UI/parser code; no fetched-binary or exfil behavior. ai
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publishing, consistent with provenance direction unchanged/improved. ai
source-diff obfuscated-file:dist/index-6BlZXZuC.js AI (source-diff): lezer-generator output bundled into dist, not obfuscation. ai
source-diff obfuscated-file:dist/decodeImage-DseBx4N0.js AI (source-diff): Bundled lodash/codemirror internals, not true obfuscation. ai
phantom-deps phantom-dep:nearley AI (phantom-deps): Build-time parser generator referenced in config, not a runtime import. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Babel preset loaded by convention in build config, not directly imported. ai
phantom-deps phantom-dep:@tailwindcss/cli AI (phantom-deps): Tailwind CLI build tool, not a runtime import. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Emotion styling lib used via convention/peer, stable false positive for this package. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS build tool referenced in build scripts/config, not a runtime import. ai
phantom-deps phantom-dep:ts-proto AI (phantom-deps): Protobuf code-gen tool used in build scripts, not a runtime import. ai

Versions (showing 27 of 27)

Version Deps Published
3.1.14 21 / 27
3.1.13 21 / 27
3.1.12 21 / 27
3.1.11 21 / 27
3.1.10 21 / 27
3.1.9 21 / 27
3.1.8 21 / 27
3.1.7 21 / 27
3.1.6 21 / 27
3.1.5 21 / 27
3.1.4 21 / 27
3.1.3 21 / 27
3.1.2 21 / 27
3.1.1 21 / 27
3.1.0 21 / 27
3.0.2 21 / 27
3.0.1 21 / 27
2.68.12 21 / 24
2.68.11 21 / 24
2.68.10 21 / 24
2.68.9 21 / 24
2.68.8 21 / 24
2.68.7 21 / 24
2.68.6 21 / 24
2.68.5 21 / 24
2.68.4 21 / 24
2.68.3 21 / 24

v3.1.13

7 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-26) provenance

This version was published by a different npm account than previous versions on 2026-03-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index--95nXh6E.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B_3PleIH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B_3PleIH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.12

5 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-25) provenance

This version was published by a different npm account than previous versions on 2026-03-25. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-8bTMarZg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.11

10 findings
HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B-g3aWAt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Be6EYnox.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Be6EYnox.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BEUjTghZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BlROWu-J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BlROWu-J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfencl → dzenda (on 2026-03-20, known maintainer) provenance

This version was published by a different npm account (dzenda) than the most recent previously approved version (davidfencl) on 2026-03-20, but dzenda is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.10

7 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BNRG4n8S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BTrKy8v9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BTrKy8v9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.9

8 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-_apLu4SL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-_apLu4SL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B_6J3epQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B9Z4uArr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.8

7 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bf5zVcAc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BG23zkos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bl1gi-zh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.7

9 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-aCoqRfTl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B4osw0hO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B7AEFuPp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B8amzXr1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B8amzXr1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.6

8 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-18) provenance

This version was published by a different npm account than previous versions on 2026-03-18. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BF6pGj6y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BF6pGj6y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bi4nJb4U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Bi4nJb4U.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.5

6 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-17) provenance

This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-0eLSwhoo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BO7SiaLV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.4

8 findings
HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-1D5S7eR3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-1D5S7eR3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-4r5XO2hY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BWUFvnnr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BWUFvnnr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.3

6 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-13) provenance

This version was published by a different npm account than previous versions on 2026-03-13. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B4QJRCC8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BIOeAcXP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.2

4 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-12) provenance

This version was published by a different npm account than previous versions on 2026-03-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

7 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-11) provenance

This version was published by a different npm account than previous versions on 2026-03-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BGnPWAxp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BN1XXU26.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BsCcQbSo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

6 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-03-06) provenance

This version was published by a different npm account than previous versions on 2026-03-06. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BFuISzq9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BimzNWm5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.2

6 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-02-25) provenance

This version was published by a different npm account than previous versions on 2026-02-25. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-ANY2H_o3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BG2Ave0p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

8 findings
HIGH Publisher changed: davidfencl → GitHub Actions (on 2026-02-20) provenance

This version was published by a different npm account than previous versions on 2026-02-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/decodeImage-DseBx4N0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-DseBx4N0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-6BlZXZuC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-7ZRO7erP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B1qvG-qo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B6jTuetX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.12

19 findings
HIGH New obfuscated file: dist/decodeImage-CknL-EpW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/decodeImage-CknL-EpW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-b6YQ8pEG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BdOnegno.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BEYdpI1P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BK7t-TNT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BmA_NU2n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BpCB5IqU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bwoa2Opb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CAirOtdy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-D_X7asPn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DBxSMLW2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DJU7lf9I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DJU7lf9I.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DwCQnAGC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-EUVKEGOd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-EUVKEGOd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: davidfencl → dzenda (on 2026-01-05, known maintainer) provenance

This version was published by a different npm account (dzenda) than the most recent previously approved version (davidfencl) on 2026-01-05, but dzenda is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.68.11

16 findings
HIGH New obfuscated file: dist/index-BArQYoU9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BLTVlMYq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BLTVlMYq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BwKQxvNs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C2eC_Z31.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C6LkfXti.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CaDtC7cf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-cih1vOnj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DAbjHYTG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Decu1Mne.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DFrPDKFQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DLslize8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-TsjtsSmF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-wxnOzmSh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-wxnOzmSh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.10

16 findings
HIGH New obfuscated file: dist/index-BNOguuXJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BQS2Zm_4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C4r5IcKB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C8J-pcJN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CF3Qalgd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Ct9xm-pq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DgJK8CVA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DgJK8CVA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Dl-BT0Go.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dtvj50qi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DV7ZF_In.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-HZpBmPlK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-HZpBmPlK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-JBRGZ0QJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-NWR-Tbbg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.9

16 findings
HIGH New obfuscated file: dist/index-AY6RFcAW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-AY6RFcAW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B6CSn3bW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bi1G4sZj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BNBWBozz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BNBWBozz.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BsdHlfPa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CmXHlFr5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-D9015yOi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dbjyr-nz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DDDjobHa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DRAiJ5eq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DTsPOb8D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-nKZICw68.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-s9z7OIka.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.8

16 findings
HIGH New obfuscated file: dist/index-1Mp2uiPR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B8WI1K1N.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BHkyh3c6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BIIHWu1p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BIIHWu1p.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BRYP3I3Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C253OuSj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CLKf126y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CPm4j5Ig.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DDTzdpi1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dh8OYuxP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DHS5r_kP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DuHl2uxK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dz5WEhSI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Dz5WEhSI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.7

16 findings
HIGH New obfuscated file: dist/index-BDj31R0x.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BJj3DCnA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BJj3DCnA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BsdXtQIu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bw4WjOoq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CGgP776P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CKt938IX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CKt938IX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D9XpMyAE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dat82IBw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DyvSbzEJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Fh-vkEN7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-nuaqVn1y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-PnkfGw6B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Yut0kJgD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.6

16 findings
HIGH New obfuscated file: dist/index-5b5DlnDp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-5b5DlnDp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-bekfXYhw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bxmz2JGo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Bxmz2JGo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C160LZiW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CEmQpnf1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CF1qeWCH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-ClaUzliw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Clx56BVl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CNrPETKn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CxQflRm0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DsRuKXXH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-fYYimNJd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-ndaPIspl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.5

16 findings
HIGH New obfuscated file: dist/index-B4F8jwBY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BAxPEhqR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BCJJS1pY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BP2oHfNr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BP2oHfNr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BWlC4GYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C5WTu0CZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Ckht5geU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Cx1MZ-Am.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-D6yjBwjb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DhDBR33Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DrsQNLUE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Q9YoPjO0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Uxn2h85I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Uxn2h85I.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.68.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.68.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.