@lynx-js/web-explorer-canary
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/static/js/async/web-worker-runtime-main-thread.js | AI (source-diff): Webpack bundle output, DOM shim code matching package purpose. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/legacy-wasm-chunk.js | AI (source-diff): Webpack-bundled wasm-bindgen glue code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/web-core-main-thread-apis.js | AI (source-diff): Webpack bundle output for wasm runtime, consistent with package purpose. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/web-core-worker-runtime.js | AI (source-diff): Webpack bundle output; worker runtime loader code matches stated function. | ai | |
| source-diff | net-exec-file:dist/static/js/async/web-core-worker-runtime.js | AI (source-diff): eval(this) pattern is a bundler global-scope trick, not dropper malware; no external network fetch target. | ai | |
| source-diff | net-exec-file:dist/static/js/async/64.js | AI (source-diff): Bundled lynx runtime code (eval-this shims), no exfil target present. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): CI/CD publisher migration within same monorepo, corroborated by SLSA provenance. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): WASM modules are part of the lynx web-core runtime, expected for this package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/64.js | AI (source-diff): Webpack bundle output for this web-platform package, not true obfuscation. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.0.17 | 0 / 8 | |
| 0.0.15 | 0 / 7 | |
| 0.0.14 | 0 / 7 | |
| 0.0.13 | 0 / 7 | |
| 0.0.11 | 0 / 7 | |
| 0.0.2 | 1 / 5 |
v0.0.15
9 findingsAll previous maintainers (lynxdev-admin, jianliang00) were replaced by new maintainers (colinaaa). This is a strong signal of a potential package hijack and requires careful review.
Package contains compiled binaries that could be backdoors: • dist/static/wasm/97be315d.module.wasm • dist/static/wasm/fbb8137e.module.wasm
This version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.14
9 findingsAll previous maintainers (lynxdev-admin, jianliang00) were replaced by new maintainers (colinaaa). This is a strong signal of a potential package hijack and requires careful review.
Package contains compiled binaries that could be backdoors: • dist/static/wasm/97be315d.module.wasm • dist/static/wasm/fbb8137e.module.wasm
This version was published by a different npm account than previous versions on 2025-12-07. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.13
9 findingsAll previous maintainers (lynxdev-admin, jianliang00) were replaced by new maintainers (colinaaa). This is a strong signal of a potential package hijack and requires careful review.
Package contains compiled binaries that could be backdoors: • dist/static/wasm/754c06ee.module.wasm • dist/static/wasm/7f8d0487.module.wasm
This version was published by a different npm account than previous versions on 2025-11-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.11
9 findingsAll previous maintainers (lynxdev-admin, jianliang00) were replaced by new maintainers (colinaaa). This is a strong signal of a potential package hijack and requires careful review.
Package contains compiled binaries that could be backdoors: • dist/static/wasm/a027d161.module.wasm • dist/static/wasm/e9aa597d.module.wasm
This version was published by a different npm account than previous versions on 2025-11-03. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.