@origintrail-official/dkg-node-ui
Web dashboard for DKG V9 nodes. Provides a browser-based UI for monitoring node health, exploring the knowledge graph, running SPARQL queries, and chatting with integrated agents.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist-ui/assets/3d-force-graph-DII0C0lY.js | AI (source-diff): Standard Vite-minified bundle of 3d-force-graph library; not malicious obfuscation. | ai | |
| source-diff | net-exec-file:dist-ui/assets/3d-force-graph-DII0C0lY.js | AI (source-diff): Network calls and dynamic code in a UI visualization bundle are expected; no exfiltration pattern. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-B6UQm9N_.js | AI (source-diff): Vite-bundled main React app entry; minification is expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-D0Mz0SVt.js | AI (source-diff): Vite-bundled D3/renderer chunk; minification is expected. | ai | |
| source-diff | net-exec-file:dist-ui/assets/index-D0Mz0SVt.js | AI (source-diff): D3 DOM manipulation bundle; network+exec pattern is false positive for this UI library. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-ByLJSVQ3.js | AI (source-diff): Vite-bundled Shiki syntax highlighter language chunks; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/jsonld-D5RXTCJi.js | AI (source-diff): Minified jsonld library bundle; expected for this DKG knowledge graph UI. | ai | |
| source-diff | net-exec-file:dist-ui/assets/jsonld-D5RXTCJi.js | AI (source-diff): jsonld library uses setImmediate polyfill with new Function; well-known pattern, not malware. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/AgentProfilePage-jB-v9soG.js | AI (source-diff): Readable minified React component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Operations-BC6Cv6cR.js | AI (source-diff): Vite-bundled UI chunk; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Network-d4igcZQ0.js | AI (source-diff): Vite-bundled UI chunk; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/OnChainProvenanceCard-BL6ou6s9.js | AI (source-diff): Vite-bundled UI chunk; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/renderer-3d-2EVDZII7-BTYEjwma.js | AI (source-diff): Vite-bundled 3D renderer chunk; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Settings-DXSjvx2a.js | AI (source-diff): Vite-bundled UI settings chunk; minification expected. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/renderer-3d-2EVDZII7-CTUExXUn.js | AI (source-diff): Vite-minified Three.js/3d renderer; standard build output. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Settings-WaFKYtwQ.js | AI (source-diff): Vite-minified UI bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/3d-force-graph-CcVMtgO4.js | AI (source-diff): Standard Vite-minified 3d-force-graph bundle; not obfuscated malware. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): False positive in string template context within viem/abitype bundle. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): jsonld library uses new Function() for context processing; documented behavior. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): Shiki syntax definition JSON for Batch files; not an actual DLL hijack command. | ai | |
| source-diff | net-exec-file:dist-ui/assets/3d-force-graph-CcVMtgO4.js | AI (source-diff): Network+exec pattern is D3/WebGL rendering library; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Admin-DNNaF7rz.js | AI (source-diff): Vite-minified UI bundle with abitype/viem code; legitimate frontend asset. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/AgentProfilePage-D2T_V6PG.js | AI (source-diff): Vite-minified React component; readable DKG ontology URIs visible in sample. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/ccip-CDdHldzo.js | AI (source-diff): Vite-minified viem CCIP read implementation; standard library code. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-2Gzrk1k3.js | AI (source-diff): Main Vite bundle with React JSX runtime license header visible; legitimate. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-BrxEjqsW.js | AI (source-diff): Vite-minified D3 selection/DOM code; standard visualization library. | ai | |
| source-diff | net-exec-file:dist-ui/assets/index-BrxEjqsW.js | AI (source-diff): D3 fetch+DOM manipulation; not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/index-W4n8cdTA.js | AI (source-diff): Vite-minified frontend bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/jsonld-DkQdPwg5.js | AI (source-diff): Vite-minified jsonld library with Digital Bazaar copyright; legitimate. | ai | |
| source-diff | net-exec-file:dist-ui/assets/jsonld-DkQdPwg5.js | AI (source-diff): jsonld library uses fetch for context loading; expected behavior. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Network-C6MDsv2e.js | AI (source-diff): Vite-minified UI bundle; standard build output. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/OnChainProvenanceCard-BbrU7jzL.js | AI (source-diff): Vite-minified React component; standard build output. | ai | |
| source-diff | obfuscated-file:dist-ui/assets/Operations-CCMDENBd.js | AI (source-diff): Vite-minified UI bundle; standard build output. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 10.0.2 | 22 / 17 | |
| 10.0.1 | 13 / 17 | |
| 10.0.0 | 13 / 17 | |
| 0.0.1 | 3 / 19 |
v10.0.2
20 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |
DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |
DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.