@netless/appliance-plugin
[中文文档](https://github.com/netless-io/fastboard/blob/main/docs/zh/appliance-plugin.md)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:cdn/fullWorker-COcCxi.js | AI (source-diff): Bundled worker code, network+exec patterns are normal app logic. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-C_hPTy.js | AI (source-diff): Minified worker bundle output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-COcCxi.js | AI (source-diff): Minified worker bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BVS4TpQx.js | AI (source-diff): Bundled app code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/index-BTyDaJHQ.mjs | AI (source-diff): Bundled app code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-BTyDaJHQ.mjs | AI (source-diff): Standard vite-bundled ESM output. | ai | |
| source-diff | obfuscated-file:dist/index-BVS4TpQx.js | AI (source-diff): Standard bundle output requiring known deps. | ai | |
| source-diff | net-exec-file:cdn/subWorker-C_hPTy.js | AI (source-diff): Bundled worker code. | ai | |
| source-diff | obfuscated-file:dist/index-BjwlxmcZ.js | AI (source-diff): Standard esbuild/vite bundle output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-D9-qHB.js | AI (source-diff): Bundled worker code, legit network usage. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-D9-qHB.js | AI (source-diff): Bundled webworker build output. | ai | |
| source-diff | obfuscated-file:dist/index-BrdMbdqX.mjs | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | net-exec-file:dist/index-BrdMbdqX.mjs | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CQ9UVK.js | AI (source-diff): Bundled webworker build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CQ9UVK.js | AI (source-diff): Bundled worker code with legit network calls for whiteboard rendering. | ai | |
| source-diff | obfuscated-file:dist/index-2kLb6nSb.js | AI (source-diff): Minified bundle requiring known libs (lodash, react, white-web-sdk). | ai | |
| source-diff | net-exec-file:dist/index-2kLb6nSb.js | AI (source-diff): Bundled dist output, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/index-BqijH7W9.js | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-DjWYcZGp.js | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-Bj1Oy7.js | AI (source-diff): Same worker bundle pattern as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-8cQCRH.js | AI (source-diff): Minified bundle; no concrete malicious network/exfil behavior shown. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-8cQCRH.js | AI (source-diff): Bundled worker output (babel helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-D-zGeAx1.js | AI (source-diff): Standard bundled dist output requiring known deps. | ai | |
| source-diff | net-exec-file:dist/index-D-zGeAx1.js | AI (source-diff): Bundled code; requires are legitimate declared deps. | ai | |
| source-diff | net-exec-file:cdn/subWorker-Bj1Oy7.js | AI (source-diff): Same worker bundle pattern as fullWorker. | ai | |
| source-diff | obfuscated-file:dist/index-DmkMw23K.mjs | AI (source-diff): Minified esbuild bundle output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-6Cu08P.js | AI (source-diff): Minified vite/babel build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-6Cu08P.js | AI (source-diff): Bundled worker code; no malicious dropper behavior observed. | ai | |
| source-diff | obfuscated-file:dist/index-DHkeFixk.js | AI (source-diff): Minified bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-DmkMw23K.mjs | AI (source-diff): Bundled code with legit imports, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Dmq7rqSP.js | AI (source-diff): Minified bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-Dmq7rqSP.js | AI (source-diff): Bundled code; legit deps only, no exfil destination. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-B3CHpe.js | AI (source-diff): Minified vite/babel build output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-B3CHpe.js | AI (source-diff): Bundled worker code, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DfV03MPS.js | AI (source-diff): esbuild/vite bundle output, requires known deps only. | ai | |
| source-diff | obfuscated-file:dist/index-DpQJ_LNL.js | AI (source-diff): esbuild/vite bundle output, requires known deps only. | ai | |
| source-diff | net-exec-file:dist/index-DpQJ_LNL.js | AI (source-diff): Bundled feature code, no malicious destination identified. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-00SXWn.js | AI (source-diff): Bundled worker output, same pattern as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/subWorker-00SXWn.js | AI (source-diff): Bundled worker output, same pattern as fullWorker. | ai | |
| source-diff | obfuscated-file:dist/index-CcTOfya8.js | AI (source-diff): esbuild/vite bundle output, requires known deps only. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-BuCr8Z.js | AI (source-diff): Minified bundle; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-BuCr8Z.js | AI (source-diff): Bundled worker output (babel/webpack helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BG79OM_x.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/index-9ShgZO4H.mjs | AI (source-diff): Bundled dist file, standard SDK code. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-BMUrhG.js | AI (source-diff): Bundled webpack worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-BMUrhG.js | AI (source-diff): Bundled worker file; network+exec pattern is normal SDK worker code. | ai | |
| source-diff | obfuscated-file:dist/index-B8PVRB8H.js | AI (source-diff): Standard esbuild/vite bundle output for this package's dist build. | ai | |
| source-diff | net-exec-file:dist/index-B8PVRB8H.js | AI (source-diff): Bundled dist file; pattern reflects normal SDK code, not dropper. | ai | |
| source-diff | net-exec-file:cdn/subWorker-CuaPMN.js | AI (source-diff): Bundled worker file, not malicious. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-CuaPMN.js | AI (source-diff): Bundled webpack worker output. | ai | |
| source-diff | obfuscated-file:dist/index-9ShgZO4H.mjs | AI (source-diff): Bundled ESM build output. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): xss and clipper-lib are well-known established packages. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-EItvTR.js | AI (source-diff): Bundled Vite/esbuild output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-EItvTR.js | AI (source-diff): Bundled worker code; no hostile network/exec behavior observed. | ai | |
| source-diff | obfuscated-file:dist/index-CKzwq6e5.js | AI (source-diff): Standard bundled dist output requiring legit deps. | ai | |
| source-diff | net-exec-file:dist/index-CKzwq6e5.js | AI (source-diff): Bundled dist file; no malicious destination identified. | ai | |
| source-diff | obfuscated-file:dist/index-etTR6iX7.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-Bo0nOl.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-Bo0nOl.js | AI (source-diff): Bundled worker code, expected pattern for whiteboard SDK. | ai | |
| source-diff | obfuscated-file:dist/index-B81IwG0_.mjs | AI (source-diff): Bundled ESM output. | ai | |
| source-diff | net-exec-file:dist/index-B81IwG0_.mjs | AI (source-diff): Bundled ESM output, dual-use pattern only. | ai | |
| source-diff | net-exec-file:dist/index-cRE5FY5s.js | AI (source-diff): Bundled SDK code, dual-use APIs not malicious. | ai | |
| source-diff | obfuscated-file:dist/index-cRE5FY5s.js | AI (source-diff): Standard bundled dist output. | ai | |
| source-diff | obfuscated-file:dist/index-BDVvqw7g.js | AI (source-diff): Standard bundled dist output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DMz46H.js | AI (source-diff): Worker/network calls are core to whiteboard rendering, not exfil. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DMz46H.js | AI (source-diff): Bundled worker script (babel helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/subWorker-B_zAQR.js | AI (source-diff): Worker/network calls inherent to plugin function. | ai | |
| source-diff | obfuscated-file:dist/index-B-Nowr4E.mjs | AI (source-diff): Standard bundled ESM output. | ai | |
| source-diff | net-exec-file:dist/index-B-Nowr4E.mjs | AI (source-diff): Bundled SDK code, not malicious. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-B_zAQR.js | AI (source-diff): Bundled worker script. | ai | |
| source-diff | obfuscated-file:dist/index-DDd3tlz2.mjs | AI (source-diff): Bundled ESM output from vite build. | ai | |
| source-diff | net-exec-file:dist/index-DDd3tlz2.mjs | AI (source-diff): Bundled ESM output, standard SDK imports. | ai | |
| source-diff | net-exec-file:cdn/subWorker-D3x__X.js | AI (source-diff): Bundled worker code, not a dropper. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-D3x__X.js | AI (source-diff): Bundled worker output mirrors fullWorker. | ai | |
| source-diff | obfuscated-file:dist/index-BwY-Y-lK.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/index-BUV3AIdR.js | AI (source-diff): Bundled SDK code requiring legit deps (white-web-sdk, lodash, react). | ai | |
| source-diff | obfuscated-file:dist/index-BUV3AIdR.js | AI (source-diff): esbuild/vite bundled dist output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-B41ROv.js | AI (source-diff): Bundled worker code; no fetched-binary or exfil behavior observed. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-B41ROv.js | AI (source-diff): Babel/vite bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DutDhB.js | AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DELSIerV.mjs | AI (source-diff): Bundled mjs file with legit imports; no malicious behavior evident. | ai | |
| source-diff | net-exec-file:dist/index-CcD-F3bG.js | AI (source-diff): Bundled dist file with legit requires; no malicious behavior evident. | ai | |
| source-diff | net-exec-file:cdn/subWorker-D52EcC.js | AI (source-diff): Worker bundle; no malicious network/exec behavior in sample, standard build artifact. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DutDhB.js | AI (source-diff): Worker bundle; no malicious network/exec behavior in sample, standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-DELSIerV.mjs | AI (source-diff): Vite bundled mjs output with normal imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CcD-F3bG.js | AI (source-diff): esbuild/vite bundled dist output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BVAZlFjO.js | AI (source-diff): esbuild/vite bundled dist output, not obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-D52EcC.js | AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-D1N3tpY5.js | AI (source-diff): Standard bundler output requiring legit deps. | ai | |
| source-diff | net-exec-file:dist/index-D1N3tpY5.js | AI (source-diff): Bundled requires of legit deps, no dropper behavior. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CvY8jJ.js | AI (source-diff): Bundled minified worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BXxVx2.js | AI (source-diff): Bundled minified worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CQhmRvRP.js | AI (source-diff): Standard bundler output requiring legit deps. | ai | |
| source-diff | obfuscated-file:dist/index-B0SzWigt.mjs | AI (source-diff): Standard bundler output requiring legit deps. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CvY8jJ.js | AI (source-diff): Worker loads own bundled script, not fetched payload execution. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BXxVx2.js | AI (source-diff): Worker loads own bundled script, not fetched payload execution. | ai | |
| source-diff | net-exec-file:dist/index-B0SzWigt.mjs | AI (source-diff): Bundled requires of legit deps, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/assets/fullWorker-JXQULSul.js | AI (source-diff): Bundler module loader pattern, no remote fetch+exec behavior. | ai | |
| source-diff | net-exec-file:dist/index-CPeyvSwP.js | AI (source-diff): Standard bundled require() calls, no hostile network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/fullWorker-JXQULSul.js | AI (source-diff): Vite/webpack bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CPeyvSwP.js | AI (source-diff): esbuild/vite CJS bundle requiring known deps, not obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DCfVcI.js | AI (source-diff): Bundled worker code with normal require/network patterns, no fetched-binary exec. | ai | |
| source-diff | obfuscated-file:dist/index-Cqizo6hB.mjs | AI (source-diff): Bundled dist output matching declared build scripts. | ai | |
| source-diff | obfuscated-file:dist/index-Ci0eJ9wV.js | AI (source-diff): Bundled dist output matching declared build scripts. | ai | |
| source-diff | net-exec-file:dist/index-Cqizo6hB.mjs | AI (source-diff): Bundled dist code, generic require/network pattern not malicious behavior. | ai | |
| source-diff | net-exec-file:dist/index-Ci0eJ9wV.js | AI (source-diff): Bundled dist code, generic require/network pattern not malicious behavior. | ai | |
| source-diff | net-exec-file:cdn/subWorker-DtUO-T.js | AI (source-diff): Bundled worker code with normal require/network patterns, no fetched-binary exec. | ai | |
| source-diff | obfuscated-file:dist/index-BVgkgGj9.js | AI (source-diff): Bundled dist output matching declared build scripts. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-DtUO-T.js | AI (source-diff): Vite/Rollup bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DCfVcI.js | AI (source-diff): Vite/Rollup bundled worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BNqxsoBb.js | AI (source-diff): Bundled dist file, benign requires only. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CIRArL.js | AI (source-diff): Bundled worker code, no concrete malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CIRArL.js | AI (source-diff): Minified worker bundle, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BNqxsoBb.js | AI (source-diff): Standard bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-DeePQlzi.mjs | AI (source-diff): Bundled dist file, standard imports only. | ai | |
| source-diff | obfuscated-file:dist/index-DeePQlzi.mjs | AI (source-diff): Bundled ESM dist output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-C_XI7b.js | AI (source-diff): Bundled worker code, no malicious behavior found. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-C_XI7b.js | AI (source-diff): Minified worker bundle. | ai | |
| source-diff | obfuscated-file:dist/index-CVBczavT.js | AI (source-diff): Bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-DoPUPDGn.js | AI (source-diff): Bundled dist file, no hostile network/exec payload observed. | ai | |
| source-diff | net-exec-file:cdn/subWorker-i4iY3L.js | AI (source-diff): Bundled CDN worker file, no hostile payload observed. | ai | |
| source-diff | net-exec-file:dist/index-rETHYLFW.mjs | AI (source-diff): Bundled dist file, no hostile payload observed. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-i4iY3L.js | AI (source-diff): Bundled worker output, same pattern as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-vQBoXq.js | AI (source-diff): Bundled CDN worker file, documented part of package, no hostile payload observed. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-vQBoXq.js | AI (source-diff): Bundled worker output (babel helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DFjstPTR.js | AI (source-diff): Standard esbuild/vite bundled dist output. | ai | |
| source-diff | obfuscated-file:dist/index-DoPUPDGn.js | AI (source-diff): Standard bundled dist output requiring legit deps (spritejs, lodash, react). | ai | |
| source-diff | obfuscated-file:dist/index-rETHYLFW.mjs | AI (source-diff): Bundled ESM dist output, standard Vite build banner. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-B5am5t.js | AI (source-diff): Standard bundled worker code, no concrete malicious network/exec behavior. | ai | |
| source-diff | net-exec-file:dist/index-C2jNkleW.js | AI (source-diff): Bundled library code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-vs0uTdYT.js | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BNBv5T.js | AI (source-diff): Same babel-generated worker bundle pattern as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BNBv5T.js | AI (source-diff): Bundled worker, not malicious exec/net behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DCVJNFKI.mjs | AI (source-diff): ESM bundle output of same library. | ai | |
| source-diff | net-exec-file:dist/index-DCVJNFKI.mjs | AI (source-diff): Bundled ESM library code. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-B5am5t.js | AI (source-diff): Bundled worker output (babel/rollup helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-C2jNkleW.js | AI (source-diff): Bundled dist output requiring known libs (lodash, react, spritejs). | ai | |
| source-diff | obfuscated-file:dist/index-Bj242vt1.mjs | AI (source-diff): Minified ESM bundle of same plugin code. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BCicGG.js | AI (source-diff): Minified worker bundle. | ai | |
| source-diff | obfuscated-file:dist/index-D6FsYoIf.js | AI (source-diff): Minified build output. | ai | |
| source-diff | obfuscated-file:dist/index-C_jpLx3X.js | AI (source-diff): Minified dist bundle of the whiteboard plugin, not obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DRJe2Z.js | AI (source-diff): Generic fetch/eval tokens in minified bundle, no concrete malicious behavior. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DRJe2Z.js | AI (source-diff): Minified build bundle, not true obfuscation; matches package's worker functionality. | ai | |
| source-diff | net-exec-file:dist/index-Bj242vt1.mjs | AI (source-diff): Pattern match on minified bundle, no malicious behavior shown. | ai | |
| source-diff | net-exec-file:dist/index-C_jpLx3X.js | AI (source-diff): Pattern match on minified bundle, no malicious destination identified. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BCicGG.js | AI (source-diff): Pattern match on minified bundle. | ai | |
| source-diff | obfuscated-file:dist/index-C8bfLLn0.mjs | AI (source-diff): Bundled esm output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-Bt73U4.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-Bt73U4.js | AI (source-diff): Minified bundle, no concrete malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-D6M2zcmo.js | AI (source-diff): Standard esbuild/rollup bundle output. | ai | |
| source-diff | net-exec-file:dist/index-D6M2zcmo.js | AI (source-diff): Bundled code requiring legit deps, no malicious destination. | ai | |
| source-diff | obfuscated-file:dist/index-yV6BCDyw.js | AI (source-diff): Bundled output. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-C1W6w_.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | net-exec-file:dist/index-C8bfLLn0.mjs | AI (source-diff): Bundled esm output, imports legit deps only. | ai | |
| source-diff | net-exec-file:cdn/subWorker-C1W6w_.js | AI (source-diff): Bundled worker output, no malicious behavior. | ai | |
| source-diff | net-exec-file:dist/assets/fullWorker-BnxU9bnt.js | AI (source-diff): Minified bundle; network+exec pattern is bundler runtime, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/fullWorker-BnxU9bnt.js | AI (source-diff): Bundled webpack worker output, not true obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Build output reorganization (new hashed bundle filenames), not injected code. | ai | |
| source-diff | net-exec-file:dist/index-09gdXQ2w.js | AI (source-diff): Bundled output, no fetched/executed remote payload observed. | ai | |
| source-diff | obfuscated-file:dist/index-09gdXQ2w.js | AI (source-diff): Vite/esbuild bundle requiring known deps (lodash, react, spritejs). | ai | |
| source-diff | obfuscated-file:cdn/subWorker-CCcMxk.js | AI (source-diff): Bundled worker output, matches fullWorker sibling. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-BLyJlo.js | AI (source-diff): Bundled worker output (Babel/Vite build artifact), not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-BLyJlo.js | AI (source-diff): Legit bundled worker requiring known deps; no hostile network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Bx3LQtc6.js | AI (source-diff): Standard minified dist bundle, requires only declared deps. | ai | |
| source-diff | obfuscated-file:dist/index-jpSMuTU2.js | AI (source-diff): Standard minified dist bundle, requires only declared deps. | ai | |
| source-diff | net-exec-file:dist/index-jpSMuTU2.js | AI (source-diff): Bundled output; no malicious network/exec behavior identified. | ai | |
| source-diff | net-exec-file:cdn/subWorker-CCcMxk.js | AI (source-diff): Bundled worker output, no hostile behavior. | ai | |
| source-diff | obfuscated-file:dist/index-CFgqSRC-.mjs | AI (source-diff): ESM bundled output with source-mapped imports of known deps. | ai | |
| source-diff | net-exec-file:dist/index-CFgqSRC-.mjs | AI (source-diff): Bundled ESM output, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index-BwLQzsnp.js | AI (source-diff): Standard vite/rollup bundle output. | ai | |
| source-diff | net-exec-file:dist/index-0fBM84zK.mjs | AI (source-diff): Bundled dist code, no fetched/executed payload observed. | ai | |
| source-diff | net-exec-file:dist/index-Wi09G9p1.js | AI (source-diff): Bundled dist code, no fetched/executed payload observed. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BA8EkW.js | AI (source-diff): Bundled worker code, no fetched/executed payload observed. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-gIfxem.js | AI (source-diff): Bundled worker code, no fetched/executed payload observed. | ai | |
| source-diff | obfuscated-file:dist/index-0fBM84zK.mjs | AI (source-diff): Standard vite/rollup ESM bundle output. | ai | |
| source-diff | obfuscated-file:dist/index-Wi09G9p1.js | AI (source-diff): Standard vite/rollup bundle output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-gIfxem.js | AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BA8EkW.js | AI (source-diff): Bundled worker output (Babel helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-B90iIvel.js | AI (source-diff): Standard esbuild/vite bundle output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DzU-Co.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-B5ZQoK.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CpjV7Ujm.js | AI (source-diff): Standard esbuild/vite bundle output. | ai | |
| source-diff | obfuscated-file:dist/index-D8AMdzYo.mjs | AI (source-diff): Standard esbuild/vite bundle output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DzU-Co.js | AI (source-diff): Requires of legit deps in bundled worker, not dropper behavior. | ai | |
| source-diff | net-exec-file:cdn/subWorker-B5ZQoK.js | AI (source-diff): Requires of legit deps in bundled worker, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-CpjV7Ujm.js | AI (source-diff): Requires of legit deps in bundled output, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-D8AMdzYo.mjs | AI (source-diff): Requires of legit deps in bundled output, not dropper behavior. | ai | |
| source-diff | net-exec-file:cdn/subWorker-CTbbnN.js | AI (source-diff): Bundled worker file, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-CTbbnN.js | AI (source-diff): Bundled worker output declared in files/cdn. | ai | |
| source-diff | obfuscated-file:dist/index-DG4OS7jZ.js | AI (source-diff): Bundled dist output, consistent with build scripts. | ai | |
| source-diff | net-exec-file:dist/index-Cj2T7zY6.js | AI (source-diff): Bundled dist file, matches package's declared build. | ai | |
| source-diff | obfuscated-file:dist/index-Cj2T7zY6.js | AI (source-diff): Standard tsup/vite bundle output for this package's dist. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-BEJqjH.js | AI (source-diff): Bundled worker file; network+exec pattern from bundler, not a dropper. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-BEJqjH.js | AI (source-diff): Bundled worker output declared in files/cdn, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C-flLj6b.mjs | AI (source-diff): Bundled dist file matching declared module field. | ai | |
| source-diff | obfuscated-file:dist/index-C-flLj6b.mjs | AI (source-diff): Bundled ESM dist output. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-XdMBFp.js | AI (source-diff): Bundled worker output (Babel/Rollup helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Dkg_PdHZ.mjs | AI (source-diff): Bundled dist file; no concrete malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Dkg_PdHZ.mjs | AI (source-diff): Vite/esbuild bundled ESM output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-ChVI4C.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-ChVI4C.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | net-exec-file:dist/index-VnPTZ-8D.js | AI (source-diff): Bundled dist file; no concrete malicious behavior. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-XdMBFp.js | AI (source-diff): Bundled worker code; pattern match on minified bundle, no malicious behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-CcOhAM6h.js | AI (source-diff): Vite/esbuild bundled dist output. | ai | |
| source-diff | obfuscated-file:dist/index-VnPTZ-8D.js | AI (source-diff): Vite/esbuild bundled dist output. | ai | |
| source-diff | obfuscated-file:dist/index-CBeudPfv.js | AI (source-diff): Bundled dist output requiring known deps (white-web-sdk, spritejs, lodash). | ai | |
| source-diff | obfuscated-file:dist/index-B42Mnde_.js | AI (source-diff): esbuild/vite bundled dist output, not obfuscation. | ai | |
| source-diff | net-exec-file:cdn/subWorker-B-aVKt.js | AI (source-diff): Bundled worker code, benign. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-B-aVKt.js | AI (source-diff): Same bundled worker pattern as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-8AH6yz.js | AI (source-diff): Bundled worker code; network/exec pattern is normal for canvas worker. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-8AH6yz.js | AI (source-diff): Babel-transpiled bundled worker output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CWXxYSm5.mjs | AI (source-diff): Bundled output pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-CWXxYSm5.mjs | AI (source-diff): Bundled ESM dist output, standard imports visible. | ai | |
| source-diff | net-exec-file:dist/index-CBeudPfv.js | AI (source-diff): Bundled output; no malicious network target identified. | ai | |
| source-diff | net-exec-file:dist/index-Bd_LdZxD.mjs | AI (source-diff): Bundled code, no dropper/exfil pattern. | ai | |
| source-diff | obfuscated-file:dist/index-Bd_LdZxD.mjs | AI (source-diff): Bundled ESM dist output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-1E_izA.js | AI (source-diff): Bundled worker code, no malicious behavior. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-1E_izA.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | obfuscated-file:dist/index-qS7tU8QD.js | AI (source-diff): Bundled dist chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-8E5yX5Xn.js | AI (source-diff): Bundled require/network calls, no malicious destination. | ai | |
| source-diff | obfuscated-file:dist/index-8E5yX5Xn.js | AI (source-diff): Standard bundled dist output matching declared build. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CnB3KR.js | AI (source-diff): Bundled worker code; no exfil/dropper behavior found. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CnB3KR.js | AI (source-diff): Bundled worker output via vite build, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-CHwEVk.js | AI (source-diff): Bundled worker output, matches fullWorker pattern. | ai | |
| source-diff | net-exec-file:dist/index-DBSetQlP.js | AI (source-diff): Bundled require() calls to known deps, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-DBSetQlP.js | AI (source-diff): esbuild/vite bundled dist output. | ai | |
| source-diff | obfuscated-file:dist/index-D6tJMnFK.js | AI (source-diff): esbuild/vite bundled dist output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CWXCEL.js | AI (source-diff): Bundled code with normal require/import, no fetched-binary execution. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CWXCEL.js | AI (source-diff): Bundled worker output (babel/vite build artifact), not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/subWorker-CHwEVk.js | AI (source-diff): Bundled worker output, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-Be0GtbHC.mjs | AI (source-diff): Bundled ESM output from vite build. | ai | |
| source-diff | net-exec-file:dist/index-Be0GtbHC.mjs | AI (source-diff): Bundled ESM output importing declared deps. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-CiM9eF.js | AI (source-diff): Minified worker bundle. | ai | |
| source-diff | obfuscated-file:dist/index-DqtwzzbR.js | AI (source-diff): Minified dist bundle. | ai | |
| source-diff | net-exec-file:dist/index-CjuLwRGu.js | AI (source-diff): Bundled build output, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-CjuLwRGu.js | AI (source-diff): Minified dist bundle from documented build pipeline. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-BOTjIN.js | AI (source-diff): Bundled build output; network+exec pattern is benign SDK code. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-BOTjIN.js | AI (source-diff): Minified worker bundle, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BJ92LABo.mjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:dist/index-BJ92LABo.mjs | AI (source-diff): Minified ESM bundle. | ai | |
| source-diff | net-exec-file:cdn/subWorker-CiM9eF.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BqoFdX.js | AI (source-diff): Minified worker bundle from vite build, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-D8qYooNV.js | AI (source-diff): Bundled build output, same pattern as sibling files. | ai | |
| source-diff | net-exec-file:dist/index-A33g679O.js | AI (source-diff): Bundled dist file requiring first-party deps, no malicious destination. | ai | |
| source-diff | obfuscated-file:dist/index-A33g679O.js | AI (source-diff): Minified bundler output, matches package's own vite build scripts. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-C9GaK9.js | AI (source-diff): Bundled worker code referencing own deps, no exfil behavior shown. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-C9GaK9.js | AI (source-diff): Minified worker bundle from documented vite build, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C3iivLNQ.mjs | AI (source-diff): Bundled mjs file importing package's declared deps only. | ai | |
| source-diff | obfuscated-file:dist/index-C3iivLNQ.mjs | AI (source-diff): ESM bundler output with @__PURE__ markers, standard build artifact. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BqoFdX.js | AI (source-diff): Bundled worker code, no exfil destination identified. | ai | |
| source-diff | obfuscated-file:dist/index-bnjZuIEN.js | AI (source-diff): Standard esbuild/vite bundle output referencing declared deps. | ai | |
| source-diff | net-exec-file:cdn/subWorker-DBZ80n.js | AI (source-diff): Bundled worker code, no evidence of malicious exfil target. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-DBZ80n.js | AI (source-diff): Same worker bundle pattern as fullWorker; build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-bnjZuIEN.js | AI (source-diff): Bundled runtime code, no malicious network destination identified. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-Bdpfgf.js | AI (source-diff): Minified bundle contains normal fetch/eval patterns from bundler runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-Bdpfgf.js | AI (source-diff): Bundled/minified worker output, not true obfuscation; matches new mermaid/markmap deps. | ai | |
| source-diff | net-exec-file:cdn/subWorker-Ctdc1N.js | AI (source-diff): Bundled worker code, same pattern as fullWorker. | ai | |
| source-diff | net-exec-file:dist/index-Zo8fc0as.mjs | AI (source-diff): Bundled ESM dist output, no exfil evidence. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CM7O_1.js | AI (source-diff): Bundled worker output for whiteboard rendering, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CM7O_1.js | AI (source-diff): Bundled worker code; network+eval pattern from bundler, no exfil destination found. | ai | |
| source-diff | obfuscated-file:dist/index-BH3BQoqB.js | AI (source-diff): Standard bundled dist output referencing known deps (white-web-sdk, spritejs). | ai | |
| source-diff | net-exec-file:dist/index-BH3BQoqB.js | AI (source-diff): Bundled dist file, no concrete malicious destination identified. | ai | |
| source-diff | obfuscated-file:dist/index-VwIhaoVA.js | AI (source-diff): Bundled dist output, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-Ctdc1N.js | AI (source-diff): Bundled worker output mirroring fullWorker. | ai | |
| source-diff | obfuscated-file:dist/index-Zo8fc0as.mjs | AI (source-diff): Bundled ESM dist output, standard vite/rollup bundling. | ai | |
| source-diff | obfuscated-file:dist/index-DKv5OrcQ.mjs | AI (source-diff): Standard vite bundle output (ESM). | ai | |
| source-diff | net-exec-file:dist/index-DKv5OrcQ.mjs | AI (source-diff): Bundled SDK code, not a dropper. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-DxZdUl.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/subWorker-5GNo7p.js | AI (source-diff): Bundled worker file, normal functionality. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-5GNo7p.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CzXLwKrb.js | AI (source-diff): Bundled SDK code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-CzXLwKrb.js | AI (source-diff): Standard bundle output requiring legitimate deps. | ai | |
| source-diff | obfuscated-file:dist/index-BTfw__T5.js | AI (source-diff): Standard vite/esbuild bundle output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-DxZdUl.js | AI (source-diff): Bundled worker file; network/eval calls are normal SDK functionality. | ai | |
| source-diff | obfuscated-file:dist/index-BAy7v2Ki.mjs | AI (source-diff): Vite/esbuild bundled ESM output. | ai | |
| source-diff | net-exec-file:dist/index-BAy7v2Ki.mjs | AI (source-diff): Bundled ESM output, no concrete malicious target. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-cbo6pm.js | AI (source-diff): Babel-transpiled worker bundle, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-cbo6pm.js | AI (source-diff): Bundled worker file; no concrete dropper behavior shown. | ai | |
| source-diff | obfuscated-file:dist/index-B6T_rYrQ.js | AI (source-diff): Standard bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-B6T_rYrQ.js | AI (source-diff): Bundled dist file, no malicious destination evident. | ai | |
| source-diff | obfuscated-file:dist/index-BppjVY_l.js | AI (source-diff): Bundled dist output. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BFcARi.js | AI (source-diff): Bundled worker output, mirrors fullWorker. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BFcARi.js | AI (source-diff): Bundled worker output, no exfil behavior. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BbF9q2.js | AI (source-diff): Bundled worker with normal fetch/require, not a dropper. | ai | |
| source-diff | net-exec-file:dist/index-OwNIkbKl.js | AI (source-diff): Bundled dist file, legitimate deps required. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CF7R0e.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BbF9q2.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-2kLI3OsH.js | AI (source-diff): Minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/index-OwNIkbKl.js | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/index-DWP99OFK.mjs | AI (source-diff): Bundled dist file, legitimate deps required. | ai | |
| source-diff | obfuscated-file:dist/index-DWP99OFK.mjs | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CF7R0e.js | AI (source-diff): Bundled worker with normal fetch/require, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-DmfRoAiB.js | AI (source-diff): Standard esbuild/vite minified dist output. | ai | |
| source-diff | net-exec-file:dist/index-CIJP6_Qj.mjs | AI (source-diff): Bundled SDK code; no hostile network target identified. | ai | |
| source-diff | obfuscated-file:dist/index-CIJP6_Qj.mjs | AI (source-diff): Standard esbuild/vite minified dist output. | ai | |
| source-diff | net-exec-file:dist/index-DmfRoAiB.js | AI (source-diff): Bundled SDK code; no hostile network target identified. | ai | |
| source-diff | obfuscated-file:dist/index-C29o_HLi.js | AI (source-diff): Standard esbuild/vite minified dist output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-DUJqv_.js | AI (source-diff): Bundled worker code; no hostile network target identified. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-DUJqv_.js | AI (source-diff): Bundled worker code, same build pipeline as fullWorker. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-CjGKnN.js | AI (source-diff): Bundled worker code; no hostile network target identified. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-CjGKnN.js | AI (source-diff): Babel/Vite-minified worker bundle, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-a-uKt6aD.js | AI (source-diff): esbuild/vite bundled dist output, matches package's stated build. | ai | |
| source-diff | net-exec-file:dist/index-a-uKt6aD.js | AI (source-diff): Bundled dist file requiring legit deps, not a loader. | ai | |
| source-diff | obfuscated-file:dist/index-BdHH_zhp.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-4wkCzC.js | AI (source-diff): Bundled worker output. | ai | |
| source-diff | net-exec-file:cdn/subWorker-4wkCzC.js | AI (source-diff): Web Worker bundle, no dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-RCWmSJU4.mjs | AI (source-diff): Vite/esbuild bundled ESM output. | ai | |
| source-diff | net-exec-file:dist/index-RCWmSJU4.mjs | AI (source-diff): Bundled ESM file, not a loader/dropper. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-uIttd_.js | AI (source-diff): Web Worker bundle, no fetched/executed remote payload. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-uIttd_.js | AI (source-diff): Bundled webpack worker output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:cdn/subWorker-BiAuBO.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| source-diff | net-exec-file:cdn/fullWorker-ZK5NZY.js | AI (source-diff): Bundled worker file; no malicious network exfil target found. | ai | |
| source-diff | obfuscated-file:cdn/fullWorker-ZK5NZY.js | AI (source-diff): Bundled worker output, not true obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): Consistent with npm-org rename; provenance direction unchanged, long track record. | ai | |
| source-diff | net-exec-file:dist/index-KFAuNRB0.mjs | AI (source-diff): Bundled ESM dist output, benign imports. | ai | |
| source-diff | obfuscated-file:dist/index-KFAuNRB0.mjs | AI (source-diff): Bundled ESM dist output. | ai | |
| source-diff | obfuscated-file:dist/index-CWK75u1P.js | AI (source-diff): Bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-BVb1IYUU.js | AI (source-diff): Bundled dist file, benign requires. | ai | |
| source-diff | obfuscated-file:dist/index-BVb1IYUU.js | AI (source-diff): Standard bundled dist output requiring known deps. | ai | |
| source-diff | net-exec-file:cdn/subWorker-BiAuBO.js | AI (source-diff): Bundled worker file; no malicious network exfil target found. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 154 versions; no provenance has been a consistent pattern, not a new risk signal. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 1.1.37 | 12 / 30 | |
| 1.1.36 | 15 / 27 | |
| 1.1.35 | 15 / 21 | |
| 1.1.34 | 15 / 21 | |
| 1.1.33 | 15 / 20 | |
| 1.1.32 | 15 / 20 | |
| 1.1.31 | 15 / 20 | |
| 1.1.30 | 15 / 20 | |
| 1.1.29 | 11 / 19 | |
| 1.1.28 | 11 / 19 | |
| 1.1.27 | 11 / 19 | |
| 1.1.26 | 11 / 19 | |
| 1.1.25 | 11 / 19 | |
| 1.1.24 | 11 / 19 | |
| 1.1.23 | 11 / 19 | |
| 1.1.16 | 9 / 12 | |
| 1.1.15 | 9 / 12 | |
| 1.1.14 | 9 / 12 | |
| 1.1.13 | 9 / 12 | |
| 1.1.12 | 9 / 12 | |
| 1.1.11 | 9 / 12 | |
| 1.1.10 | 9 / 12 | |
| 1.1.9 | 9 / 12 | |
| 1.1.8 | 9 / 12 | |
| 1.1.7 | 9 / 12 | |
| 1.1.6 | 9 / 12 | |
| 1.1.5 | 9 / 12 | |
| 1.1.4 | 9 / 12 | |
| 1.1.3 | 9 / 12 | |
| 1.1.2 | 9 / 12 | |
| 1.1.1 | 9 / 12 | |
| 1.1.0 | 9 / 12 | |
| 1.0.10 | 9 / 12 | |
| 1.0.9 | 9 / 12 | |
| 1.0.8 | 9 / 12 | |
| 1.0.7 | 9 / 12 | |
| 1.0.6 | 9 / 12 | |
| 1.0.4 | 9 / 12 | |
| 1.0.3 | 9 / 12 | |
| 1.0.2 | 9 / 12 | |
| 1.0.1 | 9 / 13 | |
| 1.0.0 | 9 / 13 |
v1.1.37
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.36
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.33
12 findingsThis version was published by a different npm account than previous versions on 2026-03-01. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.32
12 findingsThis version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.31
12 findingsThis version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.30
12 findingsThis version was published by a different npm account than previous versions on 2026-01-29. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.29
11 findingsThis version was published by a different npm account than previous versions on 2026-01-13. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.28
11 findingsThis version was published by a different npm account than previous versions on 2025-12-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.27
11 findingsThis version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.26
11 findingsThis version was published by a different npm account than previous versions on 2025-11-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.25
11 findingsThis version was published by a different npm account than previous versions on 2025-11-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.24
11 findingsThis version was published by a different npm account than previous versions on 2025-11-14. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.23
11 findingsThis version was published by a different npm account than previous versions on 2025-11-06. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.16
11 findingsThis version was published by a different npm account than previous versions on 2025-03-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.15
11 findingsThis version was published by a different npm account than previous versions on 2025-03-20. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.14
11 findingsThis version was published by a different npm account than previous versions on 2025-03-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.13
11 findingsThis version was published by a different npm account than previous versions on 2025-03-07. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.12
11 findingsThis version was published by a different npm account than previous versions on 2025-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.11
11 findingsThis version was published by a different npm account than previous versions on 2025-03-04. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.10
11 findingsThis version was published by a different npm account than previous versions on 2025-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.9
11 findingsThis version was published by a different npm account than previous versions on 2025-02-08. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.8
11 findingsThis version was published by a different npm account than previous versions on 2025-01-08. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.7
11 findingsThis version was published by a different npm account than previous versions on 2024-12-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.6
11 findingsThis version was published by a different npm account than previous versions on 2024-12-02. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
11 findingsThis version was published by a different npm account than previous versions on 2024-11-28. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
11 findingsThis version was published by a different npm account than previous versions on 2024-11-14. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.3
11 findingsThis version was published by a different npm account than previous versions on 2024-11-13. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
11 findingsThis version was published by a different npm account than previous versions on 2024-11-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
11 findingsThis version was published by a different npm account than previous versions on 2024-10-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
11 findingsThis version was published by a different npm account than previous versions on 2024-10-08. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.10
11 findingsThis version was published by a different npm account than previous versions on 2024-09-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
11 findingsThis version was published by a different npm account than previous versions on 2024-09-20. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.6
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.