← Home

@mapsindoors/map-template

Get a MapsIndoors map up and running in less than 10 mins.

35
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

timi_mapspeoplematb5303madh_mapspeopleanluccwolfoj

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/reactcomponent-2Oa1vSiK.mjs AI (source-diff): Bundled React wrapper output; no malicious behavior identified. ai
source-diff obfuscated-file:dist/MapboxMap-b8e1f7b9.mjs AI (source-diff): Bundled mapbox-gl output, minified not obfuscated. ai
maintainer-change maintainer-removed AI (maintainer-change): Team roster churn, not indicative of takeover here. ai
source-diff net-exec-file:dist/mi-keyboard.entry-863c3e6f.mjs AI (source-diff): Bundled simple-keyboard lib, fetch+eval pattern is library code. ai
source-diff net-exec-file:dist/reactcomponent-a0e7be60.mjs AI (source-diff): Bundled mapbox worker code triggers pattern, not real dropper. ai
source-diff obfuscated-file:dist/reactcomponent-a0e7be60.mjs AI (source-diff): Bundled shared chunk, minified build output. ai
source-diff obfuscated-file:dist/loader.js AI (source-diff): Stencil bundler output, not obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-BrPGG2Eb.mjs AI (source-diff): Bundled React wrapper output, not a dropper. ai
source-diff obfuscated-file:dist/mi-keyboard.entry.js AI (source-diff): Rollup-bundled component, banner confirms bundler output. ai
source-diff obfuscated-file:dist/MapboxMap-B6KoqPhx.mjs AI (source-diff): Bundled mapbox-gl vendor code, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-ClcNu0Jp.mjs AI (source-diff): False positive on bundled react/react-dom chunk, no dropper behavior. ai
source-diff obfuscated-file:dist/reactcomponent-ClcNu0Jp.mjs AI (source-diff): Bundled react vendor code, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-CXGF3cup.mjs AI (source-diff): False positive from bundled React internals, no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/MapboxMap-DPgB89sY.mjs AI (source-diff): Bundled mapbox-gl/react output, not true obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-CXGF3cup.mjs AI (source-diff): Bundled react/react-dom output, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-BN24n8tO.mjs AI (source-diff): Mapbox-gl worker Blob URL pattern, not a dropper/loader. ai
source-diff obfuscated-file:dist/reactcomponent-BN24n8tO.mjs AI (source-diff): Vite-bundled React vendor chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/MapboxMap-mz9e1-Xj.mjs AI (source-diff): Vite-bundled mapbox-gl/react output, minified not obfuscated. ai
source-diff obfuscated-file:dist/reactcomponent-BmMjGXfA.mjs AI (source-diff): Minified bundled react/react-dom vendor code, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-BmMjGXfA.mjs AI (source-diff): Bundled worker-loader pattern from mapbox-gl, no exfil behavior. ai
source-diff obfuscated-file:dist/MapboxMap-CSVlFDmp.mjs AI (source-diff): Minified bundled mapbox-gl vendor code, not true obfuscation. ai
source-diff obfuscated-file:dist/MapboxMap-99e1280c.mjs AI (source-diff): Bundled mapbox-gl/rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/mi-keyboard.entry-c7c21089.mjs AI (source-diff): simple-keyboard bundled lib; no exfil target, dual-use pattern-match false positive. ai
source-diff net-exec-file:dist/reactcomponent-29a2f430.mjs AI (source-diff): Shared bundled chunk (mapbox worker), not a loader/dropper. ai
source-diff net-exec-file:dist/reactcomponent-E5EHkbbU.mjs AI (source-diff): Standard bundled library code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/MapboxMap-DoVKZdim.mjs AI (source-diff): Bundled mapbox-gl/react output, not true obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-E5EHkbbU.mjs AI (source-diff): Bundled React/react-dom output, minified not obfuscated. ai
source-diff obfuscated-file:dist/MapboxMap-EuKWsGtq.mjs AI (source-diff): Bundled mapbox-gl vendor code, long lines from minification not obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-DcNpL3XF.mjs AI (source-diff): React bundle network+eval pattern is standard bundler output, not a dropper. ai
source-diff obfuscated-file:dist/reactcomponent-DcNpL3XF.mjs AI (source-diff): Bundled react/react-dom vendor code, minified not obfuscated. ai
source-diff net-exec-file:dist/reactcomponent-591cbab2.mjs AI (source-diff): Bundled mapbox-gl worker code, network+eval is library's own worker bootstrap. ai
source-diff obfuscated-file:dist/reactcomponent-591cbab2.mjs AI (source-diff): Bundled vendor libs (mapbox-gl etc.) via rollup, minified not obfuscated. ai
source-diff net-exec-file:dist/mi-keyboard.entry-3d4cd664.mjs AI (source-diff): Bundled simple-keyboard lib, no malicious network/exec behavior found. ai
source-diff net-exec-file:dist/reactcomponent-60ae3cf8.mjs AI (source-diff): Bundled library code (webpack-style module loader), not a dropper. ai
source-diff obfuscated-file:dist/MapboxMap-543e96b0.mjs AI (source-diff): Bundled mapbox-gl dependency code, not obfuscation. ai
source-diff net-exec-file:dist/mi-keyboard.entry-a9fbdfd9.mjs AI (source-diff): Bundled simple-keyboard third-party lib, no external fetch/exec behavior. ai
source-diff obfuscated-file:dist/reactcomponent-60ae3cf8.mjs AI (source-diff): Rollup bundle of React component wrapper, standard minified output. ai
source-diff net-exec-file:dist/reactcomponent-YR-wqqnq.mjs AI (source-diff): Minified bundle false positive; no actual dropper behavior in sample. ai
source-diff obfuscated-file:dist/MapboxMap-B2ZZYj9A.mjs AI (source-diff): Bundled Vite/mapbox-gl output, not true obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-YR-wqqnq.mjs AI (source-diff): Bundled react/react-dom vendored code, not obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-e02cfc96.mjs AI (source-diff): Bundled Stencil/React runtime shim, minified not obfuscated. ai
source-diff obfuscated-file:dist/MapboxMap-88d2bbda.mjs AI (source-diff): Rollup-bundled mapbox-gl worker code, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-e02cfc96.mjs AI (source-diff): Bundled worker/blob pattern from mapbox-gl, not a loader payload. ai
source-diff net-exec-file:dist/mi-keyboard.entry-240f425f.mjs AI (source-diff): Bundled simple-keyboard vendor lib, dynamic-code pattern is library internal, not exfil. ai
source-diff obfuscated-file:dist/MapboxMap-9897ca13.mjs AI (source-diff): Bundled mapbox-gl/react vendor code, not obfuscation. ai
source-diff net-exec-file:dist/mi-keyboard.entry-59acfa72.mjs AI (source-diff): Bundled simple-keyboard lib, no exfil behavior. ai
source-diff net-exec-file:dist/reactcomponent-ce833545.mjs AI (source-diff): Worker-blob creation from bundled mapbox-gl, standard pattern. ai
source-diff obfuscated-file:dist/reactcomponent-ce833545.mjs AI (source-diff): Shared Rollup vendor chunk (react-component helpers). ai
source-diff net-exec-file:dist/reactcomponent-BbCjFBSB.mjs AI (source-diff): Bundled react code; no fetched/executed remote payload found. ai
source-diff obfuscated-file:dist/MapboxMap-BnjSSnYk.mjs AI (source-diff): Bundled mapbox-gl/react vendor chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/reactcomponent-BbCjFBSB.mjs AI (source-diff): Bundled react vendor chunk, minified not obfuscated. ai
dependencies unvetted-dep:@mapsindoors/components AI (dependencies): Same-org sibling package, wildcard version normal for monorepo. ai
source-diff obfuscated-file:dist/MapboxMap-2ca661fb.mjs AI (source-diff): Bundled mapbox-gl/rollup output, not obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-bfc3d486.mjs AI (source-diff): Bundled shared component chunk, standard build output. ai
source-diff net-exec-file:dist/reactcomponent-bfc3d486.mjs AI (source-diff): Bundled mapbox-gl worker code triggers pattern; not malicious behavior. ai
source-diff net-exec-file:dist/mi-keyboard.entry-8cfafea4.mjs AI (source-diff): simple-keyboard bundled lib; no fetched/exec'd remote code. ai
source-diff net-exec-file:dist/reactcomponent-Gjza9Ks-.mjs AI (source-diff): False positive: standard bundled React internals, no real network+eval malware pattern. ai
source-diff obfuscated-file:dist/reactcomponent-Gjza9Ks-.mjs AI (source-diff): Minified react/react-dom vendor bundle, not obfuscation. ai
source-diff obfuscated-file:dist/MapboxMap-CzhLW1aD.mjs AI (source-diff): Minified mapbox-gl/vite bundle output, not obfuscation. ai
source-diff net-exec-file:dist/mi-keyboard.entry-b52f9f9a.mjs AI (source-diff): Bundled simple-keyboard vendor lib, not dropper behavior. ai
source-diff net-exec-file:dist/reactcomponent-c954508d.mjs AI (source-diff): Bundled mapbox-gl worker code, network+eval pattern is from vendored lib not injected malware. ai
source-diff obfuscated-file:dist/MapboxMap-cdeb43d4.mjs AI (source-diff): Rollup-bundled mapbox-gl dependency, minified not obfuscated. ai
source-diff obfuscated-file:dist/reactcomponent-c954508d.mjs AI (source-diff): Shared bundled chunk for web components, minified build output. ai
source-diff net-exec-file:dist/mi-keyboard.entry-54c78b95.mjs AI (source-diff): Bundled simple-keyboard vendor lib; no exfil target, standard minified output. ai
source-diff net-exec-file:dist/reactcomponent-44b70bf6.mjs AI (source-diff): Shared Stencil/Rollup runtime chunk; network+eval patterns are bundler artifacts. ai
source-diff obfuscated-file:dist/MapboxMap-7877a6f9.mjs AI (source-diff): Bundled mapbox-gl worker code, minified build output not obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-914d4e50.mjs AI (source-diff): Bundled shared chunk; net+eval usage is from vendored libs (mapbox-gl worker), not malicious. ai
source-diff obfuscated-file:dist/reactcomponent-914d4e50.mjs AI (source-diff): Shared Rollup bundle chunk of React component wrappers, minified build output. ai
source-diff net-exec-file:dist/mi-keyboard.entry-aef67e92.mjs AI (source-diff): Bundled simple-keyboard lib; network+eval usage is library-internal, not exfil. ai
source-diff obfuscated-file:dist/MapboxMap-a9485d4a.mjs AI (source-diff): Bundled mapbox-gl dependency chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/reactcomponent-BKgRXBbo.mjs AI (source-diff): Bundled React/jsx runtime output from Vite build. ai
source-diff obfuscated-file:dist/MapboxMap-Cy4NgRAi.mjs AI (source-diff): Bundled mapbox-gl/vendor code, not true obfuscation. ai
source-diff net-exec-file:dist/reactcomponent-BKgRXBbo.mjs AI (source-diff): Mapbox-gl WebWorker bundling shim, not dropper malware. ai
bogus-package bogus-package AI (bogus-package): Established long-running package (1149 days, 332 versions); missing repo field is a metadata gap, not spam. ai
source-diff net-exec-file:dist/mi-keyboard.entry.js AI (source-diff): Stencil component bundle; false positive pattern match, no malicious network call. ai
source-diff net-exec-file:dist/polyfills/core-js.js AI (source-diff): core-js polyfill; net+exec pattern is bundler artifact, no real network exfil. ai
source-diff obfuscated-file:dist/polyfills/core-js.js AI (source-diff): core-js polyfill bundle, standard minified library, not obfuscated malware. ai
source-diff obfuscated-file:dist/MapboxMap-4def7f8c.mjs AI (source-diff): Bundled mapbox-gl/rollup output, not obfuscation. ai
source-diff obfuscated-file:dist/reactcomponent-39094f44.mjs AI (source-diff): Bundled shared rollup chunk for web components. ai
source-diff net-exec-file:dist/reactcomponent-39094f44.mjs AI (source-diff): False positive on bundled libs combining fetch + eval-like polyfills, no exfil target. ai
source-diff net-exec-file:dist/mi-keyboard.entry-93aae114.mjs AI (source-diff): Bundled simple-keyboard vendor lib; no malicious network/exec behavior. ai
maintainer-change maintainer-added AI (maintainer-change): Consistent with known-maintainer manual publish per provenance note. ai
source-diff obfuscated-file:dist/MapboxMap-424a8535.mjs AI (source-diff): Bundled mapbox-gl dist output, not obfuscation. ai
source-diff net-exec-file:dist/mi-keyboard.entry-11d4f6fa.mjs AI (source-diff): Bundled simple-keyboard lib, benign. ai
source-diff net-exec-file:dist/reactcomponent-7da8ab64.mjs AI (source-diff): mapbox-gl worker/blob URL pattern, not a dropper. ai
source-diff obfuscated-file:dist/reactcomponent-7da8ab64.mjs AI (source-diff): Bundled stencil/rollup dist output. ai
source-diff obfuscated-file:dist/reactcomponent-D62sCClk.mjs AI (source-diff): Standard Vite-minified React component bundle; recognizable React internals in sample, not obfuscated malware. ai
source-diff net-exec-file:dist/reactcomponent-D62sCClk.mjs AI (source-diff): Network+exec pattern fires on Mapbox WebWorker blob construction, a well-known legitimate pattern in mapbox-gl bundles. ai
source-diff obfuscated-file:dist/MapboxMap-VzEIQBJd.mjs AI (source-diff): Standard Vite-minified bundle containing Mapbox-GL and React code; long-lived package with consistent build pattern. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Declared runtime dep; config-file-only reference is a known heuristic false positive. ai
phantom-deps phantom-dep:@mapsindoors/components AI (phantom-deps): Same-org dep; phantom detection is a heuristic false positive for monorepo-style packages. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Declared runtime dep; config-file-only reference is a known heuristic false positive. ai
phantom-deps phantom-dep:react-modal-sheet AI (phantom-deps): Declared runtime dep; config-file-only reference is a known heuristic false positive. ai
phantom-deps phantom-dep:motion AI (phantom-deps): Declared runtime dep; config-file-only reference is a known heuristic false positive. ai
phantom-deps phantom-dep:@mapsindoors/css AI (phantom-deps): Same-org dep; phantom detection is a heuristic false positive for monorepo-style packages. ai

Versions (showing 35 of 35)

Version Deps Published
1.99.6 6 / 36
1.99.4 6 / 36
1.98.3 6 / 36
1.98.1 6 / 30
1.97.8 6 / 31
1.97.7 6 / 31
1.97.6 6 / 31
1.96.24 6 / 31
1.96.22 4 / 32
1.96.21 4 / 32
1.96.19 4 / 32
1.96.18 4 / 32
1.96.12 4 / 32
1.96.8 4 / 32
1.96.5 4 / 32
1.96.3 4 / 32
1.96.1 4 / 32
1.95.9 4 / 32
1.95.4 2 / 34
1.95.2 2 / 34
1.94.1 2 / 34
1.94.0 2 / 34
1.92.0 2 / 34
1.91.5 2 / 35
1.91.3 2 / 35
1.91.2 2 / 35
1.91.0 2 / 35
1.90.2 0 / 35
1.90.1 0 / 35
1.89.5 0 / 35
1.89.3 0 / 35
1.89.2 0 / 35
1.87.11 0 / 35
1.87.9 0 / 35
1.87.3 0 / 35

v1.97.7

4 findings
HIGH New obfuscated file: dist/MapboxMap-DPgB89sY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-CXGF3cup.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-CXGF3cup.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.96.24

4 findings
HIGH New obfuscated file: dist/MapboxMap-B6KoqPhx.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-ClcNu0Jp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-ClcNu0Jp.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.96.19

5 findings
HIGH New obfuscated file: dist/MapboxMap-CSVlFDmp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BmMjGXfA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BmMjGXfA.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-26, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-26, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.18

5 findings
HIGH New obfuscated file: dist/MapboxMap-Cy4NgRAi.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BKgRXBbo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BKgRXBbo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-26, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-26, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.12

5 findings
HIGH New obfuscated file: dist/MapboxMap-B2ZZYj9A.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-YR-wqqnq.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-YR-wqqnq.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-19, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-19, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.8

5 findings
HIGH New obfuscated file: dist/MapboxMap-CzhLW1aD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-Gjza9Ks-.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-Gjza9Ks-.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-17, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-17, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.5

5 findings
HIGH New obfuscated file: dist/MapboxMap-BnjSSnYk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-09, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-09, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.3

5 findings
HIGH New obfuscated file: dist/MapboxMap-BnjSSnYk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-09, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-09, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.96.1

5 findings
HIGH New obfuscated file: dist/MapboxMap-BnjSSnYk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BbCjFBSB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-06, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-06, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.95.9

5 findings
HIGH New obfuscated file: dist/MapboxMap-EuKWsGtq.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-DcNpL3XF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-DcNpL3XF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-05, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-05, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.95.4

21 findings
HIGH New obfuscated file: dist/loader.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-components.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-data-table.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/mi-keyboard.entry.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-location-booking.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/MapboxMap-JSpSXMbZ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-BrPGG2Eb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-BrPGG2Eb.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-04, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-04, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.95.2

21 findings
HIGH New obfuscated file: dist/loader.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-components.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-data-table.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/mi-keyboard.entry.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-location-booking.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/MapboxMap-B1oo7IUm.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-2Oa1vSiK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-2Oa1vSiK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-03-03, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-03-03, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.1

22 findings
HIGH New obfuscated file: dist/polyfills/core-js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/polyfills/core-js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/polyfills/css-shim.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/loader.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-components.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-data-table.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/mi-keyboard.entry.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-location-booking.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/polyfills/system.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-26, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-26, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.94.0

22 findings
HIGH New obfuscated file: dist/polyfills/core-js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/polyfills/core-js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/polyfills/css-shim.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/loader.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-components.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-data-table.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/mi-keyboard.entry.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-location-booking.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/polyfills/system.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-26, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-26, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.92.0

19 findings
HIGH New obfuscated file: dist/MapboxMap-7877a6f9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-f8a2c0cb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-afc9df27.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-e2144d5d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-4c780ed4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-749f8bc5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-1fee702f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-54c78b95.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-54c78b95.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-ecfc7ad4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-09a9150e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-915030aa.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-a2bea62b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-ab84dbde.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-a92a810a.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-44b70bf6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-44b70bf6.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-17, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-17, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.91.5

19 findings
HIGH New obfuscated file: dist/MapboxMap-2ca661fb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-01ad46fc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-b0f8a924.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-3f5691a9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-7700d7fc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-6b22506e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-5de0bbdf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-8cfafea4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-8cfafea4.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-26f840c8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-1ed78955.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-f9fa033f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-3ec29abf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-3e334d08.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-d889637f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-bfc3d486.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-bfc3d486.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-13, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-13, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.91.3

19 findings
HIGH New obfuscated file: dist/MapboxMap-dcd10bac.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-1f22bf66.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-b6346fe5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-bcafaa68.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-2b0e71ab.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-40f99767.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-818db2e2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-3d4cd664.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-3d4cd664.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-907c5fef.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-6ea32d85.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-40da0b7d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-a681486b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-30df17b4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-ae6eafd5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-591cbab2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-591cbab2.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-11, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-11, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.91.2

19 findings
HIGH New obfuscated file: dist/MapboxMap-88d2bbda.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-1156a090.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-69a88225.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-2af9d54d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-27271846.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-0154e517.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-973992c6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-240f425f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-240f425f.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-2df2caeb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-8b701ca9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-3820381e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-180449cf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-cc2607b1.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-d5ea07d5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-e02cfc96.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-e02cfc96.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-02-04, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-02-04, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.91.0

19 findings
HIGH New obfuscated file: dist/MapboxMap-99e1280c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-f5f50cf7.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-ee3b921a.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-f36b7315.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-29fa8cf1.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-98b205d2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-699a8ec4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-c7c21089.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-c7c21089.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-86b6c4b5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-6c97d299.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-d27403ba.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-e1bb16f5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-07315fc8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-b24c7eeb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-29a2f430.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-29a2f430.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-01-27, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-01-27, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.90.2

19 findings
HIGH New obfuscated file: dist/MapboxMap-cdeb43d4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-0e024d93.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-70920c70.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-f744b2b0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-7a927902.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-09b573ed.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-554875da.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-b52f9f9a.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-b52f9f9a.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-d0482a06.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-9cb43f9c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-e4a62317.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-481a9fa2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-8b58568e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-2677405d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-c954508d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-c954508d.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-01-20, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-01-20, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.90.1

19 findings
HIGH New obfuscated file: dist/MapboxMap-a9485d4a.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-ff39bb43.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-75fcf2b5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-e7ea52d8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-8fef4018.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-9699fa8f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-5156cfdc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-aef67e92.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-aef67e92.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-725ba020.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-54aa64fd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-733bf891.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-83bc3418.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-53b92004.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-efc96d9c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-914d4e50.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-914d4e50.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2026-01-15, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2026-01-15, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.89.5

19 findings
HIGH New obfuscated file: dist/MapboxMap-543e96b0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-37677e7b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-dfcdc5b6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-b7bae3ad.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-0bb0160b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-051d9003.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-e11499a7.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-a9fbdfd9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-a9fbdfd9.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-27de7763.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-e62647e2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-c40b8bb2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-03e80002.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-74e8d98b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-09757f7e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-60ae3cf8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-60ae3cf8.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2025-12-16, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2025-12-16, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.89.3

19 findings
HIGH New obfuscated file: dist/MapboxMap-b8e1f7b9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-8ff7f333.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-08d62fff.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-8550c599.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-77eae2f6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-f2865978.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-e725795f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-863c3e6f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-863c3e6f.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-bc20d3e1.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-38323978.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-5e3ea857.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-be06029e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-8c1f01d8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-589de936.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-a0e7be60.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-a0e7be60.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2025-12-16, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2025-12-16, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.89.2

19 findings
HIGH New obfuscated file: dist/MapboxMap-4def7f8c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-5e280243.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-a25bc003.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-38fdabfe.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-c2092d97.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-1c8e2c37.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-a07a669e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-93aae114.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-93aae114.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-b509de62.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-a5f9563e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-ce668a41.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-4ae16267.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-f963323c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-03f29b65.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-39094f44.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-39094f44.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2025-12-16, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2025-12-16, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.87.11

19 findings
HIGH New obfuscated file: dist/MapboxMap-9897ca13.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-e1609959.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-5f49516b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-496dd798.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-9423c9b7.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-3dde104c.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-23a4f234.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-59acfa72.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-59acfa72.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-17da27b2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-3eeb3de6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-86511920.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-857f12dd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-f7b1fdfd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-a06a5341.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-ce833545.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-ce833545.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2025-11-18, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2025-11-18, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.87.9

19 findings
HIGH New obfuscated file: dist/MapboxMap-424a8535.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-chip.entry-4c85308b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-combo-box.entry-7bc39e78.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-data-table.entry-9c8901d7.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-distance_2.entry-6d531e6e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-dropdown.entry-c2cae281.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-floor-selector.entry-8d3a67a9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-keyboard.entry-11d4f6fa.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/mi-keyboard.entry-11d4f6fa.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/mi-location-booking.entry-efd4293f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-googlemaps.entry-8b1e9536.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-map-mapbox.entry-069b44b7.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-my-position.entry-080afc7e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/mi-scroll-buttons.entry-79bf03f5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mi-share-sms.entry-bda4d9cf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/reactcomponent-7da8ab64.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/reactcomponent-7da8ab64.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ammapspeople → matb5303 (on 2025-11-17, known maintainer) provenance

This version was published by a different npm account (matb5303) than the most recent previously approved version (ammapspeople) on 2025-11-17, but matb5303 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.87.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.