@mseva/digit-ui-module-ptr
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/index.modern.js | AI (source-diff): Bundled build output (microbundle) containing lodash/react, not a loader/dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by added sourcemaps/unminified bundle from standard build tooling. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Known maintainer resuming publishing; consistent with prior approved history. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across the @mseva/digit-ui-* module family; not indicative of malice. | ai | |
| phantom-deps | phantom-dep:microbundle-crl | AI (phantom-deps): Build tool referenced in scripts, not imported; expected pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Large org-internal module suite; missing metadata is a style issue, not a spam/malware indicator given 255 versions and 421-day history. | ai | |
| phantom-deps | phantom-dep:@mseva/digit-ui-libraries | AI (phantom-deps): Same-org dep used indirectly via re-exports; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a peer/bundled dep common in UI module packages; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:redux-thunk | AI (phantom-deps): redux-thunk used via config/middleware wiring, not direct import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash.merge | AI (phantom-deps): Utility likely used indirectly; stable false positive for this package. | ai |
Versions (showing 51 of 87)
| Version | Deps | Published |
|---|---|---|
| 1.3.9 | 13 / 0 | |
| 1.3.8 | 13 / 0 | |
| 1.3.6 | 13 / 0 | |
| 1.3.5 | 13 / 0 | |
| 1.3.4 | 13 / 0 | |
| 1.3.3 | 13 / 0 | |
| 1.3.1 | 13 / 0 | |
| 1.2.9 | 13 / 0 | |
| 1.2.6 | 13 / 0 | |
| 1.2.5 | 13 / 0 | |
| 1.2.2 | 13 / 0 | |
| 1.2.1 | 13 / 0 | |
| 1.1.99 | 13 / 0 | |
| 1.1.98 | 13 / 0 | |
| 1.1.97 | 13 / 0 | |
| 1.1.95 | 13 / 0 | |
| 1.1.94 | 13 / 0 | |
| 1.1.93 | 13 / 0 | |
| 1.1.92 | 13 / 0 | |
| 1.1.91 | 13 / 0 | |
| 1.1.90 | 13 / 0 | |
| 1.1.89 | 13 / 0 | |
| 1.1.88 | 13 / 0 | |
| 1.1.87 | 13 / 0 | |
| 1.1.86 | 13 / 0 | |
| 1.1.85 | 13 / 0 | |
| 1.1.84 | 13 / 0 | |
| 1.1.83 | 13 / 0 | |
| 1.1.82 | 13 / 0 | |
| 1.1.80 | 13 / 0 | |
| 1.1.79 | 13 / 0 | |
| 1.1.78 | 13 / 0 | |
| 1.1.77 | 13 / 0 | |
| 1.1.75 | 13 / 0 | |
| 1.1.74 | 13 / 0 | |
| 1.1.73 | 13 / 0 | |
| 1.1.70 | 13 / 0 | |
| 1.1.69 | 13 / 0 | |
| 1.1.67 | 13 / 0 | |
| 1.1.65 | 13 / 0 | |
| 1.1.64 | 13 / 0 | |
| 1.1.62 | 13 / 0 | |
| 1.1.61 | 13 / 0 | |
| 1.1.60 | 13 / 0 | |
| 1.1.59 | 13 / 0 | |
| 1.1.58 | 13 / 0 | |
| 1.1.56 | 13 / 0 | |
| 1.1.55 | 13 / 0 | |
| 1.1.53 | 13 / 0 | |
| 1.1.52 | 13 / 0 | |
| 1.1.49 | 13 / 0 |
v1.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2026-03-14, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2026-03-03, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anou1234) than the most recent previously approved version (aashishgkpmg4) on 2026-02-09, but anou1234 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anou1234) than the most recent previously approved version (aashishgkpmg4) on 2026-02-06, but anou1234 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anou1234) than the most recent previously approved version (aashishgkpmg4) on 2026-02-02, but anou1234 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2026-01-13, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.99
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anou1234) than the most recent previously approved version (aashishgkpmg4) on 2026-01-09, but anou1234 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.98
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2026-01-07, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.97
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mujibalam2000) than the most recent previously approved version (aashishgkpmg4) on 2026-01-05, but mujibalam2000 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.95
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2026-01-02, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.94
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-31, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.93
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-24, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.92
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-22, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.91
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-19, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.90
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.89
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-17, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.88
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.87
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.86
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-15, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.84
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-12-12, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.80
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (anujsingh32) on 2025-12-10, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.77
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-12-05, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.75
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-12-03, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.74
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-12-03, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.73
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (aashishgkpmg4) than the most recent previously approved version (saurabhsingh0001) on 2025-12-02, but aashishgkpmg4 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.70
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-12-02, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.69
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-12-02, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.64
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (aashishgkpmg4) on 2025-11-27, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.61
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-20, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.60
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-19, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.59
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-18, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.58
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (anujsingh32) than the most recent previously approved version (saurabhsingh0001) on 2025-11-17, but anujsingh32 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.56
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nayandhawan) than the most recent previously approved version (saurabhsingh0001) on 2025-11-14, but nayandhawan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.