← Home

@midscene/harmony

HarmonyOS automation library for Midscene

32
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

quanruzhoushawyuyutaotaojingkai.zhao

Keywords

HarmonyOS UI automationHarmonyOS AI testingHarmonyOS automation libraryHarmonyOS automation toolHarmonyOS NEXT

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:static/static/js/index.6becfe23.js AI (source-diff): Network calls are image URLs for branding assets; dynamic code execution is webpack module system boilerplate, not dropper behavior. ai
source-diff obfuscated-file:static/static/js/index.6becfe23.js AI (source-diff): Standard webpack bundle for UI playground; source map included, content is React app code, not malicious obfuscation. ai
source-diff net-exec-file:static/static/js/index.ef742dc1.js AI (source-diff): Network calls are to midscenejs.com CDN for logo images; dynamic code is standard webpack module loading, not dropper behavior. ai
source-diff obfuscated-file:static/static/js/index.ef742dc1.js AI (source-diff): Standard webpack-bundled React UI (Midscene playground); minification is expected, not obfuscation. ai
source-diff obfuscated-file:static/static/js/index.42764323.js AI (source-diff): Standard webpack-minified React UI bundle; license header and readable React code confirm no obfuscation. ai
source-diff net-exec-file:static/static/js/index.42764323.js AI (source-diff): Network calls and dynamic requires are part of the webpack module system in a React UI bundle, not dropper behavior. ai
source-diff net-exec-file:static/static/js/index.b9bba0b1.js AI (source-diff): Network refs are CDN image URLs; dynamic code is webpack module loader pattern, not dropper. ai
source-diff obfuscated-file:static/static/js/index.b9bba0b1.js AI (source-diff): Standard webpack minified bundle for playground UI; not obfuscated malware. ai
source-diff net-exec-file:static/static/js/index.19bb7176.js AI (source-diff): Network refs are CDN image URLs for Midscene logo; no dropper/loader behavior present. ai
source-diff obfuscated-file:static/static/js/index.19bb7176.js AI (source-diff): Standard webpack-minified frontend bundle for playground UI; content is legitimate React/UI code. ai
source-diff net-exec-file:static/static/js/index.c3c091dd.js AI (source-diff): Network calls are CDN image URLs; dynamic execution is webpack module resolution, consistent with bundled SPA. ai
provenance publisher-changed AI (provenance): Transition from human publisher to GitHub Actions CI with SLSA provenance is expected for a mature monorepo; not a takeover signal. ai
source-diff obfuscated-file:static/static/js/index.c3c091dd.js AI (source-diff): Webpack-bundled React playground UI; sample shows React/JSX rendering with midscenejs.com logo URLs, no malicious content. ai
source-diff net-exec-file:static/static/js/index.acaa5ec1.js AI (source-diff): Network calls are static CDN image URLs for branding; dynamic requires are webpack module loading. ai
source-diff obfuscated-file:static/static/js/index.acaa5ec1.js AI (source-diff): Standard webpack-minified React/playground bundle; not obfuscated malware. ai
source-diff obfuscated-file:static/static/js/index.a9399388.js AI (source-diff): Standard webpack-minified bundle for playground UI; not obfuscated malware. ai
source-diff net-exec-file:static/static/js/index.a9399388.js AI (source-diff): Network calls and dynamic requires are webpack module loading patterns in a bundled frontend asset. ai
source-diff net-exec-file:static/static/js/596.5426be9e.js AI (source-diff): Network calls and dynamic requires are webpack module loading patterns in a bundled frontend asset. ai
source-diff obfuscated-file:static/static/js/596.5426be9e.js AI (source-diff): Standard webpack-minified bundle for playground UI; not obfuscated malware. ai
source-diff net-exec-file:static/static/js/index.5bb455e1.js AI (source-diff): Network calls and dynamic requires are standard webpack module patterns in a browser UI bundle, not dropper behavior. ai
source-diff obfuscated-file:static/static/js/index.5bb455e1.js AI (source-diff): Minified frontend bundle (webpack/Rspack output) for playground UI; not obfuscated malware. ai
source-diff obfuscated-file:static/static/js/889.c8e2e995.js AI (source-diff): Standard webpack-minified frontend bundle for the playground UI; not obfuscated malware. ai
source-diff net-exec-file:static/static/js/889.c8e2e995.js AI (source-diff): Network calls in this bundle are React UI asset loads (CDN images), not dropper behavior. ai
source-diff obfuscated-file:static/static/js/index.7d3d953d.js AI (source-diff): Standard webpack-minified frontend bundle; minification is expected for this package's static UI. ai
source-diff net-exec-file:static/static/js/index.7d3d953d.js AI (source-diff): Network references are CDN image URLs for the Midscene logo; no code execution from network. ai
source-diff obfuscated-file:static/static/js/index.ff17879b.js AI (source-diff): Standard webpack minified bundle for UI playground; not obfuscated malware. ai
source-diff net-exec-file:static/static/js/382.f480feba.js AI (source-diff): Network calls and dynamic requires are webpack module loading patterns, not dropper behavior. ai
source-diff net-exec-file:static/static/js/index.ff17879b.js AI (source-diff): Network calls and dynamic requires are webpack module loading patterns, not dropper behavior. ai
source-diff obfuscated-file:static/static/js/382.f480feba.js AI (source-diff): Standard webpack minified bundle for UI playground; not obfuscated malware. ai
source-diff obfuscated-file:static/static/js/index.8f7b788e.js AI (source-diff): Minified webpack/Rsbuild frontend bundle for playground UI; not obfuscation, stable pattern for this package. ai
source-diff net-exec-file:static/static/js/index.8f7b788e.js AI (source-diff): Network calls and dynamic requires in a bundled React UI are expected; no dropper behavior evident in sample. ai
source-diff net-exec-file:static/static/js/259.5d781a39.js AI (source-diff): Network+exec pattern is webpack module infrastructure and Ant Design UI code, not dropper/loader malware. ai
source-diff obfuscated-file:static/static/js/259.5d781a39.js AI (source-diff): Webpack-bundled Ant Design UI component library code for the playground UI — standard minified frontend bundle. ai
source-diff obfuscated-file:static/static/js/async/236.a5d2c1b1.js AI (source-diff): Emscripten-compiled tinyH264 WASM decoder — standard minified output for a video decoding library, not obfuscated malware. ai
source-diff net-exec-file:static/static/js/index.b4e7770b.js AI (source-diff): Network calls are for AI model API access (OpenAI), dynamic execution is webpack module system — expected for Midscene's playground UI. ai
source-diff obfuscated-file:static/static/js/index.b4e7770b.js AI (source-diff): Webpack-bundled Midscene playground UI with AI model config — standard minified frontend bundle for a developer tool. ai
source-diff obfuscated-file:static/static/js/index.b2ea9324.js AI (source-diff): This is a standard webpack-minified frontend bundle for the Midscene playground UI. The static/ directory is an expected build artifact for this HarmonyOS automation library's web interface. ai
source-diff net-exec-file:static/static/js/index.b2ea9324.js AI (source-diff): Network calls and dynamic code execution in a browser-side AI testing playground bundle are expected. The file is a legitimate minified frontend asset, not dropper/loader malware. ai
source-diff obfuscated-file:static/static/js/603.d858267a.js AI (source-diff): Standard webpack-minified frontend bundle for the @midscene/playground UI; long lines are minification artifacts, not obfuscation. ai
source-diff net-exec-file:static/static/js/index.96b6047b.js AI (source-diff): Network refs are CDN image URLs and midscenejs.com links; code execution pattern is webpack module loading, not eval/dropper behavior. ai
source-diff obfuscated-file:static/static/js/index.96b6047b.js AI (source-diff): Standard webpack-minified frontend bundle for the @midscene/playground UI; long lines are minification artifacts, not obfuscation. ai
source-diff net-exec-file:static/static/js/603.d858267a.js AI (source-diff): Network refs are CDN image URLs; code execution pattern is webpack module loading (n(id)), not eval/dropper behavior. ai
source-diff net-exec-file:static/static/js/index.3828a5f8.js AI (source-diff): Network calls and module loading in this bundle are legitimate: it's a frontend app for an AI automation tool that calls LLM APIs. No dropper/loader patterns visible in the sample. ai
source-diff obfuscated-file:static/static/js/index.3828a5f8.js AI (source-diff): This is a standard webpack/rspack minified frontend bundle for the Midscene playground UI. Content-hashed filenames and minification are expected for this package's static assets. ai
source-diff obfuscated-file:static/static/js/index.25ae0da0.js AI (source-diff): Standard webpack bundle for @midscene/playground UI; minification is expected. Content references Midscene-specific env vars and AI model config. ai
source-diff net-exec-file:static/static/js/index.25ae0da0.js AI (source-diff): Webpack bundle for playground UI; network calls are to AI APIs (core product function), dynamic execution is webpack module loading. Not dropper behavior. ai
source-diff net-exec-file:static/static/js/537.7bdd012b.js AI (source-diff): Webpack chunk for playground UI; network calls are to AI APIs (core product function), dynamic execution is webpack module loading. Not dropper behavior. ai
source-diff obfuscated-file:static/static/js/537.7bdd012b.js AI (source-diff): Standard webpack bundle for @midscene/playground UI; minification is expected. Content is Ant Design color utilities, not malware. ai
provenance no-provenance AI (provenance): Midscene packages consistently lack provenance attestation; this is a stable characteristic of the package family, not a per-version anomaly. ai

Versions (showing 32 of 32)

Version Deps Published
1.8.7 5 / 6
1.8.6 5 / 6
1.8.5 5 / 6
1.8.4 5 / 6
1.8.3 5 / 6
1.8.2 5 / 6
1.8.1 5 / 6
1.8.0 5 / 6
1.7.10 5 / 6
1.7.9 5 / 6
1.7.7 5 / 6
1.7.6 5 / 6
1.7.5 5 / 6
1.7.4 5 / 6
1.7.3 5 / 6
1.7.2 5 / 6
1.7.1 5 / 6
1.7.0 5 / 6
1.6.4 5 / 6
1.6.3 5 / 6
1.6.2 5 / 6
1.6.1 5 / 6
1.6.0 5 / 6
1.5.8 5 / 6
1.5.7 5 / 6
1.5.6 5 / 6
1.5.5 5 / 6
1.5.4 5 / 6
1.5.3 5 / 6
1.5.2 5 / 6
1.5.1 5 / 6
1.5.0 5 / 6

v1.8.7

3 findings
HIGH New obfuscated file: static/static/js/index.6becfe23.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.6becfe23.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.6

4 findings
HIGH Publisher changed: quanru → GitHub Actions (on 2026-05-27) provenance

This version was published by a different npm account than previous versions on 2026-05-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: static/static/js/index.42764323.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.42764323.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.5

4 findings
HIGH Publisher changed: quanru → GitHub Actions (on 2026-05-26) provenance

This version was published by a different npm account than previous versions on 2026-05-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: static/static/js/index.ef742dc1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.ef742dc1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.4

6 findings
HIGH Publisher changed: quanru → GitHub Actions (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: static/static/js/596.5426be9e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/596.5426be9e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.c3c091dd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.c3c091dd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.3

5 findings
HIGH New obfuscated file: static/static/js/596.5426be9e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/596.5426be9e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.b9bba0b1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.b9bba0b1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.2

5 findings
HIGH New obfuscated file: static/static/js/596.5426be9e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/596.5426be9e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.a9399388.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.a9399388.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.1

5 findings
HIGH New obfuscated file: static/static/js/596.5426be9e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/596.5426be9e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.acaa5ec1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.acaa5ec1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

5 findings
HIGH New obfuscated file: static/static/js/889.c8e2e995.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/889.c8e2e995.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.7d3d953d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.7d3d953d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.10

3 findings
HIGH New obfuscated file: static/static/js/index.19bb7176.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.19bb7176.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.9

3 findings
HIGH New obfuscated file: static/static/js/index.5bb455e1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.5bb455e1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.7

5 findings
HIGH New obfuscated file: static/static/js/382.f480feba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/382.f480feba.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.ff17879b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.ff17879b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.4

5 findings
HIGH New obfuscated file: static/static/js/603.d858267a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/603.d858267a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.96b6047b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.96b6047b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.3

5 findings
HIGH New obfuscated file: static/static/js/537.7bdd012b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/537.7bdd012b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.25ae0da0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.25ae0da0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

3 findings
HIGH New obfuscated file: static/static/js/index.3828a5f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.3828a5f8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.8

6 findings
HIGH New obfuscated file: static/static/js/async/236.a5d2c1b1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: static/static/js/259.5d781a39.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/259.5d781a39.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: static/static/js/index.b4e7770b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.b4e7770b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.7

3 findings
HIGH New obfuscated file: static/static/js/index.b2ea9324.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: static/static/js/index.b2ea9324.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.