← Home

@netless/appliance-plugin

[中文文档](https://github.com/netless-io/fastboard/blob/main/docs/zh/appliance-plugin.md)

42
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

huaguzhengvince-hzhqer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:cdn/fullWorker-COcCxi.js AI (source-diff): Bundled worker code, network+exec patterns are normal app logic. ai
source-diff obfuscated-file:cdn/subWorker-C_hPTy.js AI (source-diff): Minified worker bundle output. ai
source-diff obfuscated-file:cdn/fullWorker-COcCxi.js AI (source-diff): Minified worker bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/index-BVS4TpQx.js AI (source-diff): Bundled app code, not a dropper. ai
source-diff net-exec-file:dist/index-BTyDaJHQ.mjs AI (source-diff): Bundled app code, not a dropper. ai
source-diff obfuscated-file:dist/index-BTyDaJHQ.mjs AI (source-diff): Standard vite-bundled ESM output. ai
source-diff obfuscated-file:dist/index-BVS4TpQx.js AI (source-diff): Standard bundle output requiring known deps. ai
source-diff net-exec-file:cdn/subWorker-C_hPTy.js AI (source-diff): Bundled worker code. ai
source-diff obfuscated-file:dist/index-BjwlxmcZ.js AI (source-diff): Standard esbuild/vite bundle output. ai
source-diff net-exec-file:cdn/subWorker-D9-qHB.js AI (source-diff): Bundled worker code, legit network usage. ai
source-diff obfuscated-file:cdn/subWorker-D9-qHB.js AI (source-diff): Bundled webworker build output. ai
source-diff obfuscated-file:dist/index-BrdMbdqX.mjs AI (source-diff): Bundled build artifact. ai
source-diff net-exec-file:dist/index-BrdMbdqX.mjs AI (source-diff): Bundled build artifact. ai
source-diff obfuscated-file:cdn/fullWorker-CQ9UVK.js AI (source-diff): Bundled webworker build output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-CQ9UVK.js AI (source-diff): Bundled worker code with legit network calls for whiteboard rendering. ai
source-diff obfuscated-file:dist/index-2kLb6nSb.js AI (source-diff): Minified bundle requiring known libs (lodash, react, white-web-sdk). ai
source-diff net-exec-file:dist/index-2kLb6nSb.js AI (source-diff): Bundled dist output, not dropper malware. ai
source-diff obfuscated-file:dist/index-BqijH7W9.js AI (source-diff): Bundled build artifact. ai
source-diff obfuscated-file:dist/index-DjWYcZGp.js AI (source-diff): Bundled build artifact. ai
source-diff obfuscated-file:cdn/subWorker-Bj1Oy7.js AI (source-diff): Same worker bundle pattern as fullWorker. ai
source-diff net-exec-file:cdn/fullWorker-8cQCRH.js AI (source-diff): Minified bundle; no concrete malicious network/exfil behavior shown. ai
source-diff obfuscated-file:cdn/fullWorker-8cQCRH.js AI (source-diff): Bundled worker output (babel helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-D-zGeAx1.js AI (source-diff): Standard bundled dist output requiring known deps. ai
source-diff net-exec-file:dist/index-D-zGeAx1.js AI (source-diff): Bundled code; requires are legitimate declared deps. ai
source-diff net-exec-file:cdn/subWorker-Bj1Oy7.js AI (source-diff): Same worker bundle pattern as fullWorker. ai
source-diff obfuscated-file:dist/index-DmkMw23K.mjs AI (source-diff): Minified esbuild bundle output. ai
source-diff obfuscated-file:cdn/fullWorker-6Cu08P.js AI (source-diff): Minified vite/babel build output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-6Cu08P.js AI (source-diff): Bundled worker code; no malicious dropper behavior observed. ai
source-diff obfuscated-file:dist/index-DHkeFixk.js AI (source-diff): Minified bundled dist output. ai
source-diff net-exec-file:dist/index-DmkMw23K.mjs AI (source-diff): Bundled code with legit imports, no dropper behavior. ai
source-diff obfuscated-file:dist/index-Dmq7rqSP.js AI (source-diff): Minified bundled dist output. ai
source-diff net-exec-file:dist/index-Dmq7rqSP.js AI (source-diff): Bundled code; legit deps only, no exfil destination. ai
source-diff obfuscated-file:cdn/subWorker-B3CHpe.js AI (source-diff): Minified vite/babel build output. ai
source-diff net-exec-file:cdn/subWorker-B3CHpe.js AI (source-diff): Bundled worker code, no malicious behavior. ai
source-diff obfuscated-file:dist/index-DfV03MPS.js AI (source-diff): esbuild/vite bundle output, requires known deps only. ai
source-diff obfuscated-file:dist/index-DpQJ_LNL.js AI (source-diff): esbuild/vite bundle output, requires known deps only. ai
source-diff net-exec-file:dist/index-DpQJ_LNL.js AI (source-diff): Bundled feature code, no malicious destination identified. ai
source-diff obfuscated-file:cdn/subWorker-00SXWn.js AI (source-diff): Bundled worker output, same pattern as fullWorker. ai
source-diff net-exec-file:cdn/subWorker-00SXWn.js AI (source-diff): Bundled worker output, same pattern as fullWorker. ai
source-diff obfuscated-file:dist/index-CcTOfya8.js AI (source-diff): esbuild/vite bundle output, requires known deps only. ai
source-diff net-exec-file:cdn/fullWorker-BuCr8Z.js AI (source-diff): Minified bundle; no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:cdn/fullWorker-BuCr8Z.js AI (source-diff): Bundled worker output (babel/webpack helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-BG79OM_x.js AI (source-diff): Bundled build output. ai
source-diff net-exec-file:dist/index-9ShgZO4H.mjs AI (source-diff): Bundled dist file, standard SDK code. ai
source-diff obfuscated-file:cdn/fullWorker-BMUrhG.js AI (source-diff): Bundled webpack worker output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-BMUrhG.js AI (source-diff): Bundled worker file; network+exec pattern is normal SDK worker code. ai
source-diff obfuscated-file:dist/index-B8PVRB8H.js AI (source-diff): Standard esbuild/vite bundle output for this package's dist build. ai
source-diff net-exec-file:dist/index-B8PVRB8H.js AI (source-diff): Bundled dist file; pattern reflects normal SDK code, not dropper. ai
source-diff net-exec-file:cdn/subWorker-CuaPMN.js AI (source-diff): Bundled worker file, not malicious. ai
source-diff obfuscated-file:cdn/subWorker-CuaPMN.js AI (source-diff): Bundled webpack worker output. ai
source-diff obfuscated-file:dist/index-9ShgZO4H.mjs AI (source-diff): Bundled ESM build output. ai
publish-pattern new-deps-added AI (publish-pattern): xss and clipper-lib are well-known established packages. ai
source-diff obfuscated-file:cdn/fullWorker-EItvTR.js AI (source-diff): Bundled Vite/esbuild output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-EItvTR.js AI (source-diff): Bundled worker code; no hostile network/exec behavior observed. ai
source-diff obfuscated-file:dist/index-CKzwq6e5.js AI (source-diff): Standard bundled dist output requiring legit deps. ai
source-diff net-exec-file:dist/index-CKzwq6e5.js AI (source-diff): Bundled dist file; no malicious destination identified. ai
source-diff obfuscated-file:dist/index-etTR6iX7.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-Bo0nOl.js AI (source-diff): Bundled worker output. ai
source-diff net-exec-file:cdn/subWorker-Bo0nOl.js AI (source-diff): Bundled worker code, expected pattern for whiteboard SDK. ai
source-diff obfuscated-file:dist/index-B81IwG0_.mjs AI (source-diff): Bundled ESM output. ai
source-diff net-exec-file:dist/index-B81IwG0_.mjs AI (source-diff): Bundled ESM output, dual-use pattern only. ai
source-diff net-exec-file:dist/index-cRE5FY5s.js AI (source-diff): Bundled SDK code, dual-use APIs not malicious. ai
source-diff obfuscated-file:dist/index-cRE5FY5s.js AI (source-diff): Standard bundled dist output. ai
source-diff obfuscated-file:dist/index-BDVvqw7g.js AI (source-diff): Standard bundled dist output. ai
source-diff net-exec-file:cdn/fullWorker-DMz46H.js AI (source-diff): Worker/network calls are core to whiteboard rendering, not exfil. ai
source-diff obfuscated-file:cdn/fullWorker-DMz46H.js AI (source-diff): Bundled worker script (babel helpers), not true obfuscation. ai
source-diff net-exec-file:cdn/subWorker-B_zAQR.js AI (source-diff): Worker/network calls inherent to plugin function. ai
source-diff obfuscated-file:dist/index-B-Nowr4E.mjs AI (source-diff): Standard bundled ESM output. ai
source-diff net-exec-file:dist/index-B-Nowr4E.mjs AI (source-diff): Bundled SDK code, not malicious. ai
source-diff obfuscated-file:cdn/subWorker-B_zAQR.js AI (source-diff): Bundled worker script. ai
source-diff obfuscated-file:dist/index-DDd3tlz2.mjs AI (source-diff): Bundled ESM output from vite build. ai
source-diff net-exec-file:dist/index-DDd3tlz2.mjs AI (source-diff): Bundled ESM output, standard SDK imports. ai
source-diff net-exec-file:cdn/subWorker-D3x__X.js AI (source-diff): Bundled worker code, not a dropper. ai
source-diff obfuscated-file:cdn/subWorker-D3x__X.js AI (source-diff): Bundled worker output mirrors fullWorker. ai
source-diff obfuscated-file:dist/index-BwY-Y-lK.js AI (source-diff): Bundled build output. ai
source-diff net-exec-file:dist/index-BUV3AIdR.js AI (source-diff): Bundled SDK code requiring legit deps (white-web-sdk, lodash, react). ai
source-diff obfuscated-file:dist/index-BUV3AIdR.js AI (source-diff): esbuild/vite bundled dist output. ai
source-diff net-exec-file:cdn/fullWorker-B41ROv.js AI (source-diff): Bundled worker code; no fetched-binary or exfil behavior observed. ai
source-diff obfuscated-file:cdn/fullWorker-B41ROv.js AI (source-diff): Babel/vite bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/fullWorker-DutDhB.js AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. ai
source-diff net-exec-file:dist/index-DELSIerV.mjs AI (source-diff): Bundled mjs file with legit imports; no malicious behavior evident. ai
source-diff net-exec-file:dist/index-CcD-F3bG.js AI (source-diff): Bundled dist file with legit requires; no malicious behavior evident. ai
source-diff net-exec-file:cdn/subWorker-D52EcC.js AI (source-diff): Worker bundle; no malicious network/exec behavior in sample, standard build artifact. ai
source-diff net-exec-file:cdn/fullWorker-DutDhB.js AI (source-diff): Worker bundle; no malicious network/exec behavior in sample, standard build artifact. ai
source-diff obfuscated-file:dist/index-DELSIerV.mjs AI (source-diff): Vite bundled mjs output with normal imports, not obfuscation. ai
source-diff obfuscated-file:dist/index-CcD-F3bG.js AI (source-diff): esbuild/vite bundled dist output, not obfuscation. ai
source-diff obfuscated-file:dist/index-BVAZlFjO.js AI (source-diff): esbuild/vite bundled dist output, not obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-D52EcC.js AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-D1N3tpY5.js AI (source-diff): Standard bundler output requiring legit deps. ai
source-diff net-exec-file:dist/index-D1N3tpY5.js AI (source-diff): Bundled requires of legit deps, no dropper behavior. ai
source-diff obfuscated-file:cdn/fullWorker-CvY8jJ.js AI (source-diff): Bundled minified worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-BXxVx2.js AI (source-diff): Bundled minified worker output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-CQhmRvRP.js AI (source-diff): Standard bundler output requiring legit deps. ai
source-diff obfuscated-file:dist/index-B0SzWigt.mjs AI (source-diff): Standard bundler output requiring legit deps. ai
source-diff net-exec-file:cdn/fullWorker-CvY8jJ.js AI (source-diff): Worker loads own bundled script, not fetched payload execution. ai
source-diff net-exec-file:cdn/subWorker-BXxVx2.js AI (source-diff): Worker loads own bundled script, not fetched payload execution. ai
source-diff net-exec-file:dist/index-B0SzWigt.mjs AI (source-diff): Bundled requires of legit deps, no dropper behavior. ai
source-diff net-exec-file:dist/assets/fullWorker-JXQULSul.js AI (source-diff): Bundler module loader pattern, no remote fetch+exec behavior. ai
source-diff net-exec-file:dist/index-CPeyvSwP.js AI (source-diff): Standard bundled require() calls, no hostile network/exec behavior. ai
source-diff obfuscated-file:dist/assets/fullWorker-JXQULSul.js AI (source-diff): Vite/webpack bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-CPeyvSwP.js AI (source-diff): esbuild/vite CJS bundle requiring known deps, not obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-DCfVcI.js AI (source-diff): Bundled worker code with normal require/network patterns, no fetched-binary exec. ai
source-diff obfuscated-file:dist/index-Cqizo6hB.mjs AI (source-diff): Bundled dist output matching declared build scripts. ai
source-diff obfuscated-file:dist/index-Ci0eJ9wV.js AI (source-diff): Bundled dist output matching declared build scripts. ai
source-diff net-exec-file:dist/index-Cqizo6hB.mjs AI (source-diff): Bundled dist code, generic require/network pattern not malicious behavior. ai
source-diff net-exec-file:dist/index-Ci0eJ9wV.js AI (source-diff): Bundled dist code, generic require/network pattern not malicious behavior. ai
source-diff net-exec-file:cdn/subWorker-DtUO-T.js AI (source-diff): Bundled worker code with normal require/network patterns, no fetched-binary exec. ai
source-diff obfuscated-file:dist/index-BVgkgGj9.js AI (source-diff): Bundled dist output matching declared build scripts. ai
source-diff obfuscated-file:cdn/subWorker-DtUO-T.js AI (source-diff): Vite/Rollup bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/fullWorker-DCfVcI.js AI (source-diff): Vite/Rollup bundled worker output, not true obfuscation. ai
source-diff net-exec-file:dist/index-BNqxsoBb.js AI (source-diff): Bundled dist file, benign requires only. ai
source-diff net-exec-file:cdn/fullWorker-CIRArL.js AI (source-diff): Bundled worker code, no concrete malicious network/exec behavior found. ai
source-diff obfuscated-file:cdn/fullWorker-CIRArL.js AI (source-diff): Minified worker bundle, not true obfuscation. ai
source-diff obfuscated-file:dist/index-BNqxsoBb.js AI (source-diff): Standard bundled dist output. ai
source-diff net-exec-file:dist/index-DeePQlzi.mjs AI (source-diff): Bundled dist file, standard imports only. ai
source-diff obfuscated-file:dist/index-DeePQlzi.mjs AI (source-diff): Bundled ESM dist output. ai
source-diff net-exec-file:cdn/subWorker-C_XI7b.js AI (source-diff): Bundled worker code, no malicious behavior found. ai
source-diff obfuscated-file:cdn/subWorker-C_XI7b.js AI (source-diff): Minified worker bundle. ai
source-diff obfuscated-file:dist/index-CVBczavT.js AI (source-diff): Bundled dist output. ai
source-diff net-exec-file:dist/index-DoPUPDGn.js AI (source-diff): Bundled dist file, no hostile network/exec payload observed. ai
source-diff net-exec-file:cdn/subWorker-i4iY3L.js AI (source-diff): Bundled CDN worker file, no hostile payload observed. ai
source-diff net-exec-file:dist/index-rETHYLFW.mjs AI (source-diff): Bundled dist file, no hostile payload observed. ai
source-diff obfuscated-file:cdn/subWorker-i4iY3L.js AI (source-diff): Bundled worker output, same pattern as fullWorker. ai
source-diff net-exec-file:cdn/fullWorker-vQBoXq.js AI (source-diff): Bundled CDN worker file, documented part of package, no hostile payload observed. ai
source-diff obfuscated-file:cdn/fullWorker-vQBoXq.js AI (source-diff): Bundled worker output (babel helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-DFjstPTR.js AI (source-diff): Standard esbuild/vite bundled dist output. ai
source-diff obfuscated-file:dist/index-DoPUPDGn.js AI (source-diff): Standard bundled dist output requiring legit deps (spritejs, lodash, react). ai
source-diff obfuscated-file:dist/index-rETHYLFW.mjs AI (source-diff): Bundled ESM dist output, standard Vite build banner. ai
source-diff net-exec-file:cdn/fullWorker-B5am5t.js AI (source-diff): Standard bundled worker code, no concrete malicious network/exec behavior. ai
source-diff net-exec-file:dist/index-C2jNkleW.js AI (source-diff): Bundled library code, not a dropper. ai
source-diff obfuscated-file:dist/index-vs0uTdYT.js AI (source-diff): Bundled build artifact. ai
source-diff obfuscated-file:cdn/subWorker-BNBv5T.js AI (source-diff): Same babel-generated worker bundle pattern as fullWorker. ai
source-diff net-exec-file:cdn/subWorker-BNBv5T.js AI (source-diff): Bundled worker, not malicious exec/net behavior. ai
source-diff obfuscated-file:dist/index-DCVJNFKI.mjs AI (source-diff): ESM bundle output of same library. ai
source-diff net-exec-file:dist/index-DCVJNFKI.mjs AI (source-diff): Bundled ESM library code. ai
source-diff obfuscated-file:cdn/fullWorker-B5am5t.js AI (source-diff): Bundled worker output (babel/rollup helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-C2jNkleW.js AI (source-diff): Bundled dist output requiring known libs (lodash, react, spritejs). ai
source-diff obfuscated-file:dist/index-Bj242vt1.mjs AI (source-diff): Minified ESM bundle of same plugin code. ai
source-diff obfuscated-file:cdn/subWorker-BCicGG.js AI (source-diff): Minified worker bundle. ai
source-diff obfuscated-file:dist/index-D6FsYoIf.js AI (source-diff): Minified build output. ai
source-diff obfuscated-file:dist/index-C_jpLx3X.js AI (source-diff): Minified dist bundle of the whiteboard plugin, not obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-DRJe2Z.js AI (source-diff): Generic fetch/eval tokens in minified bundle, no concrete malicious behavior. ai
source-diff obfuscated-file:cdn/fullWorker-DRJe2Z.js AI (source-diff): Minified build bundle, not true obfuscation; matches package's worker functionality. ai
source-diff net-exec-file:dist/index-Bj242vt1.mjs AI (source-diff): Pattern match on minified bundle, no malicious behavior shown. ai
source-diff net-exec-file:dist/index-C_jpLx3X.js AI (source-diff): Pattern match on minified bundle, no malicious destination identified. ai
source-diff net-exec-file:cdn/subWorker-BCicGG.js AI (source-diff): Pattern match on minified bundle. ai
source-diff obfuscated-file:dist/index-C8bfLLn0.mjs AI (source-diff): Bundled esm output. ai
source-diff obfuscated-file:cdn/fullWorker-Bt73U4.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-Bt73U4.js AI (source-diff): Minified bundle, no concrete malicious network/exec behavior. ai
source-diff obfuscated-file:dist/index-D6M2zcmo.js AI (source-diff): Standard esbuild/rollup bundle output. ai
source-diff net-exec-file:dist/index-D6M2zcmo.js AI (source-diff): Bundled code requiring legit deps, no malicious destination. ai
source-diff obfuscated-file:dist/index-yV6BCDyw.js AI (source-diff): Bundled output. ai
source-diff obfuscated-file:cdn/subWorker-C1W6w_.js AI (source-diff): Bundled worker output. ai
source-diff net-exec-file:dist/index-C8bfLLn0.mjs AI (source-diff): Bundled esm output, imports legit deps only. ai
source-diff net-exec-file:cdn/subWorker-C1W6w_.js AI (source-diff): Bundled worker output, no malicious behavior. ai
source-diff net-exec-file:dist/assets/fullWorker-BnxU9bnt.js AI (source-diff): Minified bundle; network+exec pattern is bundler runtime, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/fullWorker-BnxU9bnt.js AI (source-diff): Bundled webpack worker output, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): Build output reorganization (new hashed bundle filenames), not injected code. ai
source-diff net-exec-file:dist/index-09gdXQ2w.js AI (source-diff): Bundled output, no fetched/executed remote payload observed. ai
source-diff obfuscated-file:dist/index-09gdXQ2w.js AI (source-diff): Vite/esbuild bundle requiring known deps (lodash, react, spritejs). ai
source-diff obfuscated-file:cdn/subWorker-CCcMxk.js AI (source-diff): Bundled worker output, matches fullWorker sibling. ai
source-diff obfuscated-file:cdn/fullWorker-BLyJlo.js AI (source-diff): Bundled worker output (Babel/Vite build artifact), not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-BLyJlo.js AI (source-diff): Legit bundled worker requiring known deps; no hostile network/exec behavior. ai
source-diff obfuscated-file:dist/index-Bx3LQtc6.js AI (source-diff): Standard minified dist bundle, requires only declared deps. ai
source-diff obfuscated-file:dist/index-jpSMuTU2.js AI (source-diff): Standard minified dist bundle, requires only declared deps. ai
source-diff net-exec-file:dist/index-jpSMuTU2.js AI (source-diff): Bundled output; no malicious network/exec behavior identified. ai
source-diff net-exec-file:cdn/subWorker-CCcMxk.js AI (source-diff): Bundled worker output, no hostile behavior. ai
source-diff obfuscated-file:dist/index-CFgqSRC-.mjs AI (source-diff): ESM bundled output with source-mapped imports of known deps. ai
source-diff net-exec-file:dist/index-CFgqSRC-.mjs AI (source-diff): Bundled ESM output, no malicious behavior. ai
source-diff obfuscated-file:dist/index-BwLQzsnp.js AI (source-diff): Standard vite/rollup bundle output. ai
source-diff net-exec-file:dist/index-0fBM84zK.mjs AI (source-diff): Bundled dist code, no fetched/executed payload observed. ai
source-diff net-exec-file:dist/index-Wi09G9p1.js AI (source-diff): Bundled dist code, no fetched/executed payload observed. ai
source-diff net-exec-file:cdn/subWorker-BA8EkW.js AI (source-diff): Bundled worker code, no fetched/executed payload observed. ai
source-diff net-exec-file:cdn/fullWorker-gIfxem.js AI (source-diff): Bundled worker code, no fetched/executed payload observed. ai
source-diff obfuscated-file:dist/index-0fBM84zK.mjs AI (source-diff): Standard vite/rollup ESM bundle output. ai
source-diff obfuscated-file:dist/index-Wi09G9p1.js AI (source-diff): Standard vite/rollup bundle output. ai
source-diff obfuscated-file:cdn/fullWorker-gIfxem.js AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-BA8EkW.js AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. ai
source-diff obfuscated-file:dist/index-B90iIvel.js AI (source-diff): Standard esbuild/vite bundle output. ai
source-diff obfuscated-file:cdn/fullWorker-DzU-Co.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-B5ZQoK.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-CpjV7Ujm.js AI (source-diff): Standard esbuild/vite bundle output. ai
source-diff obfuscated-file:dist/index-D8AMdzYo.mjs AI (source-diff): Standard esbuild/vite bundle output. ai
source-diff net-exec-file:cdn/fullWorker-DzU-Co.js AI (source-diff): Requires of legit deps in bundled worker, not dropper behavior. ai
source-diff net-exec-file:cdn/subWorker-B5ZQoK.js AI (source-diff): Requires of legit deps in bundled worker, not dropper behavior. ai
source-diff net-exec-file:dist/index-CpjV7Ujm.js AI (source-diff): Requires of legit deps in bundled output, not dropper behavior. ai
source-diff net-exec-file:dist/index-D8AMdzYo.mjs AI (source-diff): Requires of legit deps in bundled output, not dropper behavior. ai
source-diff net-exec-file:cdn/subWorker-CTbbnN.js AI (source-diff): Bundled worker file, not a loader/dropper. ai
source-diff obfuscated-file:cdn/subWorker-CTbbnN.js AI (source-diff): Bundled worker output declared in files/cdn. ai
source-diff obfuscated-file:dist/index-DG4OS7jZ.js AI (source-diff): Bundled dist output, consistent with build scripts. ai
source-diff net-exec-file:dist/index-Cj2T7zY6.js AI (source-diff): Bundled dist file, matches package's declared build. ai
source-diff obfuscated-file:dist/index-Cj2T7zY6.js AI (source-diff): Standard tsup/vite bundle output for this package's dist. ai
source-diff net-exec-file:cdn/fullWorker-BEJqjH.js AI (source-diff): Bundled worker file; network+exec pattern from bundler, not a dropper. ai
source-diff obfuscated-file:cdn/fullWorker-BEJqjH.js AI (source-diff): Bundled worker output declared in files/cdn, not true obfuscation. ai
source-diff net-exec-file:dist/index-C-flLj6b.mjs AI (source-diff): Bundled dist file matching declared module field. ai
source-diff obfuscated-file:dist/index-C-flLj6b.mjs AI (source-diff): Bundled ESM dist output. ai
source-diff obfuscated-file:cdn/fullWorker-XdMBFp.js AI (source-diff): Bundled worker output (Babel/Rollup helpers), not true obfuscation. ai
source-diff net-exec-file:dist/index-Dkg_PdHZ.mjs AI (source-diff): Bundled dist file; no concrete malicious behavior. ai
source-diff obfuscated-file:dist/index-Dkg_PdHZ.mjs AI (source-diff): Vite/esbuild bundled ESM output. ai
source-diff net-exec-file:cdn/subWorker-ChVI4C.js AI (source-diff): Bundled worker output. ai
source-diff obfuscated-file:cdn/subWorker-ChVI4C.js AI (source-diff): Bundled worker output. ai
source-diff net-exec-file:dist/index-VnPTZ-8D.js AI (source-diff): Bundled dist file; no concrete malicious behavior. ai
source-diff net-exec-file:cdn/fullWorker-XdMBFp.js AI (source-diff): Bundled worker code; pattern match on minified bundle, no malicious behavior found. ai
source-diff obfuscated-file:dist/index-CcOhAM6h.js AI (source-diff): Vite/esbuild bundled dist output. ai
source-diff obfuscated-file:dist/index-VnPTZ-8D.js AI (source-diff): Vite/esbuild bundled dist output. ai
source-diff obfuscated-file:dist/index-CBeudPfv.js AI (source-diff): Bundled dist output requiring known deps (white-web-sdk, spritejs, lodash). ai
source-diff obfuscated-file:dist/index-B42Mnde_.js AI (source-diff): esbuild/vite bundled dist output, not obfuscation. ai
source-diff net-exec-file:cdn/subWorker-B-aVKt.js AI (source-diff): Bundled worker code, benign. ai
source-diff obfuscated-file:cdn/subWorker-B-aVKt.js AI (source-diff): Same bundled worker pattern as fullWorker. ai
source-diff net-exec-file:cdn/fullWorker-8AH6yz.js AI (source-diff): Bundled worker code; network/exec pattern is normal for canvas worker. ai
source-diff obfuscated-file:cdn/fullWorker-8AH6yz.js AI (source-diff): Babel-transpiled bundled worker output, not obfuscation. ai
source-diff net-exec-file:dist/index-CWXxYSm5.mjs AI (source-diff): Bundled output pattern, not dropper behavior. ai
source-diff obfuscated-file:dist/index-CWXxYSm5.mjs AI (source-diff): Bundled ESM dist output, standard imports visible. ai
source-diff net-exec-file:dist/index-CBeudPfv.js AI (source-diff): Bundled output; no malicious network target identified. ai
source-diff net-exec-file:dist/index-Bd_LdZxD.mjs AI (source-diff): Bundled code, no dropper/exfil pattern. ai
source-diff obfuscated-file:dist/index-Bd_LdZxD.mjs AI (source-diff): Bundled ESM dist output. ai
source-diff net-exec-file:cdn/subWorker-1E_izA.js AI (source-diff): Bundled worker code, no malicious behavior. ai
source-diff obfuscated-file:cdn/subWorker-1E_izA.js AI (source-diff): Bundled worker output. ai
source-diff obfuscated-file:dist/index-qS7tU8QD.js AI (source-diff): Bundled dist chunk, not obfuscation. ai
source-diff net-exec-file:dist/index-8E5yX5Xn.js AI (source-diff): Bundled require/network calls, no malicious destination. ai
source-diff obfuscated-file:dist/index-8E5yX5Xn.js AI (source-diff): Standard bundled dist output matching declared build. ai
source-diff net-exec-file:cdn/fullWorker-CnB3KR.js AI (source-diff): Bundled worker code; no exfil/dropper behavior found. ai
source-diff obfuscated-file:cdn/fullWorker-CnB3KR.js AI (source-diff): Bundled worker output via vite build, not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-CHwEVk.js AI (source-diff): Bundled worker output, matches fullWorker pattern. ai
source-diff net-exec-file:dist/index-DBSetQlP.js AI (source-diff): Bundled require() calls to known deps, not a dropper. ai
source-diff obfuscated-file:dist/index-DBSetQlP.js AI (source-diff): esbuild/vite bundled dist output. ai
source-diff obfuscated-file:dist/index-D6tJMnFK.js AI (source-diff): esbuild/vite bundled dist output. ai
source-diff net-exec-file:cdn/fullWorker-CWXCEL.js AI (source-diff): Bundled code with normal require/import, no fetched-binary execution. ai
source-diff obfuscated-file:cdn/fullWorker-CWXCEL.js AI (source-diff): Bundled worker output (babel/vite build artifact), not true obfuscation. ai
source-diff net-exec-file:cdn/subWorker-CHwEVk.js AI (source-diff): Bundled worker output, not a dropper. ai
source-diff obfuscated-file:dist/index-Be0GtbHC.mjs AI (source-diff): Bundled ESM output from vite build. ai
source-diff net-exec-file:dist/index-Be0GtbHC.mjs AI (source-diff): Bundled ESM output importing declared deps. ai
source-diff obfuscated-file:cdn/subWorker-CiM9eF.js AI (source-diff): Minified worker bundle. ai
source-diff obfuscated-file:dist/index-DqtwzzbR.js AI (source-diff): Minified dist bundle. ai
source-diff net-exec-file:dist/index-CjuLwRGu.js AI (source-diff): Bundled build output, not a dropper. ai
source-diff obfuscated-file:dist/index-CjuLwRGu.js AI (source-diff): Minified dist bundle from documented build pipeline. ai
source-diff net-exec-file:cdn/fullWorker-BOTjIN.js AI (source-diff): Bundled build output; network+exec pattern is benign SDK code. ai
source-diff obfuscated-file:cdn/fullWorker-BOTjIN.js AI (source-diff): Minified worker bundle, not true obfuscation. ai
source-diff net-exec-file:dist/index-BJ92LABo.mjs AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/index-BJ92LABo.mjs AI (source-diff): Minified ESM bundle. ai
source-diff net-exec-file:cdn/subWorker-CiM9eF.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:cdn/subWorker-BqoFdX.js AI (source-diff): Minified worker bundle from vite build, not malicious obfuscation. ai
source-diff obfuscated-file:dist/index-D8qYooNV.js AI (source-diff): Bundled build output, same pattern as sibling files. ai
source-diff net-exec-file:dist/index-A33g679O.js AI (source-diff): Bundled dist file requiring first-party deps, no malicious destination. ai
source-diff obfuscated-file:dist/index-A33g679O.js AI (source-diff): Minified bundler output, matches package's own vite build scripts. ai
source-diff net-exec-file:cdn/fullWorker-C9GaK9.js AI (source-diff): Bundled worker code referencing own deps, no exfil behavior shown. ai
source-diff obfuscated-file:cdn/fullWorker-C9GaK9.js AI (source-diff): Minified worker bundle from documented vite build, not true obfuscation. ai
source-diff net-exec-file:dist/index-C3iivLNQ.mjs AI (source-diff): Bundled mjs file importing package's declared deps only. ai
source-diff obfuscated-file:dist/index-C3iivLNQ.mjs AI (source-diff): ESM bundler output with @__PURE__ markers, standard build artifact. ai
source-diff net-exec-file:cdn/subWorker-BqoFdX.js AI (source-diff): Bundled worker code, no exfil destination identified. ai
source-diff obfuscated-file:dist/index-bnjZuIEN.js AI (source-diff): Standard esbuild/vite bundle output referencing declared deps. ai
source-diff net-exec-file:cdn/subWorker-DBZ80n.js AI (source-diff): Bundled worker code, no evidence of malicious exfil target. ai
source-diff obfuscated-file:cdn/subWorker-DBZ80n.js AI (source-diff): Same worker bundle pattern as fullWorker; build output not obfuscation. ai
source-diff net-exec-file:dist/index-bnjZuIEN.js AI (source-diff): Bundled runtime code, no malicious network destination identified. ai
source-diff net-exec-file:cdn/fullWorker-Bdpfgf.js AI (source-diff): Minified bundle contains normal fetch/eval patterns from bundler runtime, not a dropper. ai
source-diff obfuscated-file:cdn/fullWorker-Bdpfgf.js AI (source-diff): Bundled/minified worker output, not true obfuscation; matches new mermaid/markmap deps. ai
source-diff net-exec-file:cdn/subWorker-Ctdc1N.js AI (source-diff): Bundled worker code, same pattern as fullWorker. ai
source-diff net-exec-file:dist/index-Zo8fc0as.mjs AI (source-diff): Bundled ESM dist output, no exfil evidence. ai
source-diff obfuscated-file:cdn/fullWorker-CM7O_1.js AI (source-diff): Bundled worker output for whiteboard rendering, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-CM7O_1.js AI (source-diff): Bundled worker code; network+eval pattern from bundler, no exfil destination found. ai
source-diff obfuscated-file:dist/index-BH3BQoqB.js AI (source-diff): Standard bundled dist output referencing known deps (white-web-sdk, spritejs). ai
source-diff net-exec-file:dist/index-BH3BQoqB.js AI (source-diff): Bundled dist file, no concrete malicious destination identified. ai
source-diff obfuscated-file:dist/index-VwIhaoVA.js AI (source-diff): Bundled dist output, minified not obfuscated. ai
source-diff obfuscated-file:cdn/subWorker-Ctdc1N.js AI (source-diff): Bundled worker output mirroring fullWorker. ai
source-diff obfuscated-file:dist/index-Zo8fc0as.mjs AI (source-diff): Bundled ESM dist output, standard vite/rollup bundling. ai
source-diff obfuscated-file:dist/index-DKv5OrcQ.mjs AI (source-diff): Standard vite bundle output (ESM). ai
source-diff net-exec-file:dist/index-DKv5OrcQ.mjs AI (source-diff): Bundled SDK code, not a dropper. ai
source-diff obfuscated-file:cdn/fullWorker-DxZdUl.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff net-exec-file:cdn/subWorker-5GNo7p.js AI (source-diff): Bundled worker file, normal functionality. ai
source-diff obfuscated-file:cdn/subWorker-5GNo7p.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff net-exec-file:dist/index-CzXLwKrb.js AI (source-diff): Bundled SDK code, not a dropper. ai
source-diff obfuscated-file:dist/index-CzXLwKrb.js AI (source-diff): Standard bundle output requiring legitimate deps. ai
source-diff obfuscated-file:dist/index-BTfw__T5.js AI (source-diff): Standard vite/esbuild bundle output. ai
source-diff net-exec-file:cdn/fullWorker-DxZdUl.js AI (source-diff): Bundled worker file; network/eval calls are normal SDK functionality. ai
source-diff obfuscated-file:dist/index-BAy7v2Ki.mjs AI (source-diff): Vite/esbuild bundled ESM output. ai
source-diff net-exec-file:dist/index-BAy7v2Ki.mjs AI (source-diff): Bundled ESM output, no concrete malicious target. ai
source-diff obfuscated-file:cdn/fullWorker-cbo6pm.js AI (source-diff): Babel-transpiled worker bundle, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-cbo6pm.js AI (source-diff): Bundled worker file; no concrete dropper behavior shown. ai
source-diff obfuscated-file:dist/index-B6T_rYrQ.js AI (source-diff): Standard bundled dist output. ai
source-diff net-exec-file:dist/index-B6T_rYrQ.js AI (source-diff): Bundled dist file, no malicious destination evident. ai
source-diff obfuscated-file:dist/index-BppjVY_l.js AI (source-diff): Bundled dist output. ai
source-diff obfuscated-file:cdn/subWorker-BFcARi.js AI (source-diff): Bundled worker output, mirrors fullWorker. ai
source-diff net-exec-file:cdn/subWorker-BFcARi.js AI (source-diff): Bundled worker output, no exfil behavior. ai
source-diff net-exec-file:cdn/subWorker-BbF9q2.js AI (source-diff): Bundled worker with normal fetch/require, not a dropper. ai
source-diff net-exec-file:dist/index-OwNIkbKl.js AI (source-diff): Bundled dist file, legitimate deps required. ai
source-diff obfuscated-file:cdn/fullWorker-CF7R0e.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-BbF9q2.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-2kLI3OsH.js AI (source-diff): Minified bundle output. ai
source-diff obfuscated-file:dist/index-OwNIkbKl.js AI (source-diff): Minified bundle output. ai
source-diff net-exec-file:dist/index-DWP99OFK.mjs AI (source-diff): Bundled dist file, legitimate deps required. ai
source-diff obfuscated-file:dist/index-DWP99OFK.mjs AI (source-diff): Minified bundle output. ai
source-diff net-exec-file:cdn/fullWorker-CF7R0e.js AI (source-diff): Bundled worker with normal fetch/require, not a dropper. ai
source-diff obfuscated-file:dist/index-DmfRoAiB.js AI (source-diff): Standard esbuild/vite minified dist output. ai
source-diff net-exec-file:dist/index-CIJP6_Qj.mjs AI (source-diff): Bundled SDK code; no hostile network target identified. ai
source-diff obfuscated-file:dist/index-CIJP6_Qj.mjs AI (source-diff): Standard esbuild/vite minified dist output. ai
source-diff net-exec-file:dist/index-DmfRoAiB.js AI (source-diff): Bundled SDK code; no hostile network target identified. ai
source-diff obfuscated-file:dist/index-C29o_HLi.js AI (source-diff): Standard esbuild/vite minified dist output. ai
source-diff net-exec-file:cdn/subWorker-DUJqv_.js AI (source-diff): Bundled worker code; no hostile network target identified. ai
source-diff obfuscated-file:cdn/subWorker-DUJqv_.js AI (source-diff): Bundled worker code, same build pipeline as fullWorker. ai
source-diff net-exec-file:cdn/fullWorker-CjGKnN.js AI (source-diff): Bundled worker code; no hostile network target identified. ai
source-diff obfuscated-file:cdn/fullWorker-CjGKnN.js AI (source-diff): Babel/Vite-minified worker bundle, not true obfuscation. ai
source-diff obfuscated-file:dist/index-a-uKt6aD.js AI (source-diff): esbuild/vite bundled dist output, matches package's stated build. ai
source-diff net-exec-file:dist/index-a-uKt6aD.js AI (source-diff): Bundled dist file requiring legit deps, not a loader. ai
source-diff obfuscated-file:dist/index-BdHH_zhp.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:cdn/subWorker-4wkCzC.js AI (source-diff): Bundled worker output. ai
source-diff net-exec-file:cdn/subWorker-4wkCzC.js AI (source-diff): Web Worker bundle, no dropper behavior found. ai
source-diff obfuscated-file:dist/index-RCWmSJU4.mjs AI (source-diff): Vite/esbuild bundled ESM output. ai
source-diff net-exec-file:dist/index-RCWmSJU4.mjs AI (source-diff): Bundled ESM file, not a loader/dropper. ai
source-diff net-exec-file:cdn/fullWorker-uIttd_.js AI (source-diff): Web Worker bundle, no fetched/executed remote payload. ai
source-diff obfuscated-file:cdn/fullWorker-uIttd_.js AI (source-diff): Bundled webpack worker output, not true obfuscation. ai
source-diff obfuscated-file:cdn/subWorker-BiAuBO.js AI (source-diff): Bundled worker output, not true obfuscation. ai
source-diff net-exec-file:cdn/fullWorker-ZK5NZY.js AI (source-diff): Bundled worker file; no malicious network exfil target found. ai
source-diff obfuscated-file:cdn/fullWorker-ZK5NZY.js AI (source-diff): Bundled worker output, not true obfuscation. ai
provenance publisher-changed AI (provenance): Consistent with npm-org rename; provenance direction unchanged, long track record. ai
source-diff net-exec-file:dist/index-KFAuNRB0.mjs AI (source-diff): Bundled ESM dist output, benign imports. ai
source-diff obfuscated-file:dist/index-KFAuNRB0.mjs AI (source-diff): Bundled ESM dist output. ai
source-diff obfuscated-file:dist/index-CWK75u1P.js AI (source-diff): Bundled dist output. ai
source-diff net-exec-file:dist/index-BVb1IYUU.js AI (source-diff): Bundled dist file, benign requires. ai
source-diff obfuscated-file:dist/index-BVb1IYUU.js AI (source-diff): Standard bundled dist output requiring known deps. ai
source-diff net-exec-file:cdn/subWorker-BiAuBO.js AI (source-diff): Bundled worker file; no malicious network exfil target found. ai
provenance no-provenance AI (provenance): Established package with 154 versions; no provenance has been a consistent pattern, not a new risk signal. ai

Versions (showing 42 of 42)

Version Deps Published
1.1.37 12 / 30
1.1.36 15 / 27
1.1.35 15 / 21
1.1.34 15 / 21
1.1.33 15 / 20
1.1.32 15 / 20
1.1.31 15 / 20
1.1.30 15 / 20
1.1.29 11 / 19
1.1.28 11 / 19
1.1.27 11 / 19
1.1.26 11 / 19
1.1.25 11 / 19
1.1.24 11 / 19
1.1.23 11 / 19
1.1.16 9 / 12
1.1.15 9 / 12
1.1.14 9 / 12
1.1.13 9 / 12
1.1.12 9 / 12
1.1.11 9 / 12
1.1.10 9 / 12
1.1.9 9 / 12
1.1.8 9 / 12
1.1.7 9 / 12
1.1.6 9 / 12
1.1.5 9 / 12
1.1.4 9 / 12
1.1.3 9 / 12
1.1.2 9 / 12
1.1.1 9 / 12
1.1.0 9 / 12
1.0.10 9 / 12
1.0.9 9 / 12
1.0.8 9 / 12
1.0.7 9 / 12
1.0.6 9 / 12
1.0.4 9 / 12
1.0.3 9 / 12
1.0.2 9 / 12
1.0.1 9 / 13
1.0.0 9 / 13

v1.1.37

18 findings
HIGH New obfuscated file: dist/assets/fullWorker-BnxU9bnt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/fullWorker-BnxU9bnt.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-09gdXQ2w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-09gdXQ2w.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bl1tLXFo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BW3Xkxk-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BW3Xkxk-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DKbaEDea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DqCdgRfA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-r9ho55PA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/markmap.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/subWorker-BsTroxB8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/subWorker-BsTroxB8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BCNBmzwR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BCNBmzwR.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-TIV0naEi.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-TIV0naEi.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.36

17 findings
HIGH New obfuscated file: dist/assets/fullWorker-JXQULSul.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/fullWorker-JXQULSul.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-6Wdw5Peg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B6Z-HNvr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BteU9Eqf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-C74ZK6xj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CPeyvSwP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CPeyvSwP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Cr7tTnaV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Cr7tTnaV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/subWorker-DhFJemMO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/subWorker-DhFJemMO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BfMoaIvs.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BfMoaIvs.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-rbiUTgEA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-rbiUTgEA.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.33

12 findings
HIGH Publisher changed: huaguzheng → hqer (on 2026-03-01) provenance

This version was published by a different npm account than previous versions on 2026-03-01. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CQ9UVK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CQ9UVK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-2kLb6nSb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-2kLb6nSb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BqijH7W9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DjWYcZGp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-D9-qHB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-D9-qHB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BrdMbdqX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BrdMbdqX.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.32

12 findings
HIGH Publisher changed: huaguzheng → hqer (on 2026-01-30) provenance

This version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-BuCr8Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-BuCr8Z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CcTOfya8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DfV03MPS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DpQJ_LNL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DpQJ_LNL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-00SXWn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-00SXWn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BA9yB27Q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BA9yB27Q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.31

12 findings
HIGH Publisher changed: huaguzheng → hqer (on 2026-01-30) provenance

This version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-8cQCRH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-8cQCRH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D-zGeAx1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-D-zGeAx1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-OfIZzgAi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-XJ7wx0mr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-Bj1Oy7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-Bj1Oy7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DiHYEAGm.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DiHYEAGm.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.30

12 findings
HIGH Publisher changed: huaguzheng → hqer (on 2026-01-29) provenance

This version was published by a different npm account than previous versions on 2026-01-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-Bdpfgf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-Bdpfgf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-bnjZuIEN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-bnjZuIEN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CgG2pg0-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DpO3MYcc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-DBZ80n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-DBZ80n.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DNtpxjD9.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DNtpxjD9.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.29

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2026-01-13) provenance

This version was published by a different npm account than previous versions on 2026-01-13. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-DutDhB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DutDhB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BVAZlFjO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CcD-F3bG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CcD-F3bG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-D52EcC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-D52EcC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DELSIerV.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DELSIerV.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.28

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-12-23) provenance

This version was published by a different npm account than previous versions on 2025-12-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CWXCEL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CWXCEL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D6tJMnFK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DBSetQlP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DBSetQlP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-CHwEVk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-CHwEVk.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Be0GtbHC.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Be0GtbHC.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.27

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-12-22) provenance

This version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-DCfVcI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DCfVcI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BVgkgGj9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Ci0eJ9wV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Ci0eJ9wV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-DtUO-T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-DtUO-T.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Cqizo6hB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Cqizo6hB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.26

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-11-27) provenance

This version was published by a different npm account than previous versions on 2025-11-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-EItvTR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-EItvTR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CKzwq6e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CKzwq6e5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-etTR6iX7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-Bo0nOl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-Bo0nOl.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B81IwG0_.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B81IwG0_.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.25

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-11-27) provenance

This version was published by a different npm account than previous versions on 2025-11-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-BLyJlo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-BLyJlo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bx3LQtc6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-jpSMuTU2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-jpSMuTU2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-CCcMxk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-CCcMxk.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CFgqSRC-.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CFgqSRC-.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.24

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-11-14) provenance

This version was published by a different npm account than previous versions on 2025-11-14. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CvY8jJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CvY8jJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CQhmRvRP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-D1N3tpY5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-D1N3tpY5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-BXxVx2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BXxVx2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B0SzWigt.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B0SzWigt.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.23

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-11-06) provenance

This version was published by a different npm account than previous versions on 2025-11-06. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-ZK5NZY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-ZK5NZY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BVb1IYUU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BVb1IYUU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CWK75u1P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-BiAuBO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BiAuBO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-KFAuNRB0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-KFAuNRB0.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.16

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-21) provenance

This version was published by a different npm account than previous versions on 2025-03-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-vQBoXq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-vQBoXq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DFjstPTR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DoPUPDGn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DoPUPDGn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-i4iY3L.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-i4iY3L.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-rETHYLFW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-rETHYLFW.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.15

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-20) provenance

This version was published by a different npm account than previous versions on 2025-03-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CM7O_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CM7O_1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BH3BQoqB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BH3BQoqB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-VwIhaoVA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-Ctdc1N.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-Ctdc1N.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Zo8fc0as.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Zo8fc0as.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.14

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-11) provenance

This version was published by a different npm account than previous versions on 2025-03-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-COcCxi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-COcCxi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BjwlxmcZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BVS4TpQx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BVS4TpQx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-C_hPTy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-C_hPTy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BTyDaJHQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BTyDaJHQ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.13

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-07) provenance

This version was published by a different npm account than previous versions on 2025-03-07. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-gIfxem.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-gIfxem.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BwLQzsnp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Wi09G9p1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Wi09G9p1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-BA8EkW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BA8EkW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-0fBM84zK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-0fBM84zK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.12

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-04) provenance

This version was published by a different npm account than previous versions on 2025-03-04. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-DxZdUl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DxZdUl.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BTfw__T5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CzXLwKrb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CzXLwKrb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-5GNo7p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-5GNo7p.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DKv5OrcQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DKv5OrcQ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.11

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-03-04) provenance

This version was published by a different npm account than previous versions on 2025-03-04. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CnB3KR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CnB3KR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-8E5yX5Xn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-8E5yX5Xn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-qS7tU8QD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-1E_izA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-1E_izA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bd_LdZxD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Bd_LdZxD.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.10

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-02-27) provenance

This version was published by a different npm account than previous versions on 2025-02-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-B5am5t.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-B5am5t.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C2jNkleW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C2jNkleW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-vs0uTdYT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-BNBv5T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BNBv5T.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DCVJNFKI.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DCVJNFKI.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-02-08) provenance

This version was published by a different npm account than previous versions on 2025-02-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-DzU-Co.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DzU-Co.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B90iIvel.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CpjV7Ujm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CpjV7Ujm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-B5ZQoK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-B5ZQoK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D8AMdzYo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-D8AMdzYo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2025-01-08) provenance

This version was published by a different npm account than previous versions on 2025-01-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-Bt73U4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-Bt73U4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D6M2zcmo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-D6M2zcmo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-yV6BCDyw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-C1W6w_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-C1W6w_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C8bfLLn0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C8bfLLn0.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-12-23) provenance

This version was published by a different npm account than previous versions on 2024-12-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-BEJqjH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-BEJqjH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Cj2T7zY6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Cj2T7zY6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DG4OS7jZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-CTbbnN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-CTbbnN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C-flLj6b.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-flLj6b.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-12-02) provenance

This version was published by a different npm account than previous versions on 2024-12-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CIRArL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CIRArL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BNqxsoBb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BNqxsoBb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CVBczavT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-C_XI7b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-C_XI7b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DeePQlzi.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DeePQlzi.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-11-28) provenance

This version was published by a different npm account than previous versions on 2024-11-28. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-XdMBFp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-XdMBFp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CcOhAM6h.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-VnPTZ-8D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-VnPTZ-8D.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-ChVI4C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-ChVI4C.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Dkg_PdHZ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Dkg_PdHZ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-11-14) provenance

This version was published by a different npm account than previous versions on 2024-11-14. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-BMUrhG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-BMUrhG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B8PVRB8H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B8PVRB8H.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BG79OM_x.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-CuaPMN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-CuaPMN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-9ShgZO4H.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-9ShgZO4H.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-11-13) provenance

This version was published by a different npm account than previous versions on 2024-11-13. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-cbo6pm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-cbo6pm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B6T_rYrQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B6T_rYrQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BppjVY_l.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-BFcARi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BFcARi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BAy7v2Ki.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BAy7v2Ki.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-11-05) provenance

This version was published by a different npm account than previous versions on 2024-11-05. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-DMz46H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DMz46H.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BDVvqw7g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-cRE5FY5s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-cRE5FY5s.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-B_zAQR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-B_zAQR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B-Nowr4E.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B-Nowr4E.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-10-30) provenance

This version was published by a different npm account than previous versions on 2024-10-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-BOTjIN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-BOTjIN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CjuLwRGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CjuLwRGu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DqtwzzbR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-CiM9eF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-CiM9eF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BJ92LABo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BJ92LABo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-10-08) provenance

This version was published by a different npm account than previous versions on 2024-10-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CjGKnN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CjGKnN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C29o_HLi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DmfRoAiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DmfRoAiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-DUJqv_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-DUJqv_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CIJP6_Qj.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CIJP6_Qj.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.10

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-09-21) provenance

This version was published by a different npm account than previous versions on 2024-09-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-CjGKnN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CjGKnN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C29o_HLi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DmfRoAiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DmfRoAiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-DUJqv_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-DUJqv_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CIJP6_Qj.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CIJP6_Qj.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.9

11 findings
HIGH Publisher changed: huaguzheng → hqer (on 2024-09-20) provenance

This version was published by a different npm account than previous versions on 2024-09-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: cdn/fullWorker-C9GaK9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-C9GaK9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-A33g679O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-A33g679O.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D8qYooNV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-BqoFdX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BqoFdX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C3iivLNQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C3iivLNQ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.8

10 findings
HIGH New obfuscated file: cdn/fullWorker-8AH6yz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-8AH6yz.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B42Mnde_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CBeudPfv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CBeudPfv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-B-aVKt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-B-aVKt.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CWXxYSm5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CWXxYSm5.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.7

10 findings
HIGH New obfuscated file: cdn/fullWorker-CF7R0e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-CF7R0e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-2kLI3OsH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-OwNIkbKl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-OwNIkbKl.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-BbF9q2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BbF9q2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DWP99OFK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DWP99OFK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.6

10 findings
HIGH New obfuscated file: cdn/fullWorker-B41ROv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-B41ROv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BUV3AIdR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BUV3AIdR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BwY-Y-lK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-D3x__X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-D3x__X.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DDd3tlz2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DDd3tlz2.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.4

10 findings
HIGH New obfuscated file: cdn/fullWorker-DRJe2Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-DRJe2Z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-C_jpLx3X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C_jpLx3X.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D6FsYoIf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-BCicGG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-BCicGG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bj242vt1.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Bj242vt1.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

10 findings
HIGH New obfuscated file: cdn/fullWorker-uIttd_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-uIttd_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-a-uKt6aD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-a-uKt6aD.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BdHH_zhp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: cdn/subWorker-4wkCzC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-4wkCzC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-RCWmSJU4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-RCWmSJU4.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

10 findings
HIGH New obfuscated file: cdn/fullWorker-6Cu08P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/fullWorker-6Cu08P.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DHkeFixk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Dmq7rqSP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Dmq7rqSP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cdn/subWorker-B3CHpe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: cdn/subWorker-B3CHpe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DmkMw23K.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DmkMw23K.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.