← Home

@origintrail-official/dkg-node-ui

Web dashboard for DKG V9 nodes. Provides a browser-based UI for monitoring node health, exploring the knowledge graph, running SPARQL queries, and chatting with integrated agents.

4
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

branarakicjurij89

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist-ui/assets/3d-force-graph-DII0C0lY.js AI (source-diff): Standard Vite-minified bundle of 3d-force-graph library; not malicious obfuscation. ai
source-diff net-exec-file:dist-ui/assets/3d-force-graph-DII0C0lY.js AI (source-diff): Network calls and dynamic code in a UI visualization bundle are expected; no exfiltration pattern. ai
source-diff obfuscated-file:dist-ui/assets/index-B6UQm9N_.js AI (source-diff): Vite-bundled main React app entry; minification is expected. ai
source-diff obfuscated-file:dist-ui/assets/index-D0Mz0SVt.js AI (source-diff): Vite-bundled D3/renderer chunk; minification is expected. ai
source-diff net-exec-file:dist-ui/assets/index-D0Mz0SVt.js AI (source-diff): D3 DOM manipulation bundle; network+exec pattern is false positive for this UI library. ai
source-diff obfuscated-file:dist-ui/assets/index-ByLJSVQ3.js AI (source-diff): Vite-bundled Shiki syntax highlighter language chunks; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/jsonld-D5RXTCJi.js AI (source-diff): Minified jsonld library bundle; expected for this DKG knowledge graph UI. ai
source-diff net-exec-file:dist-ui/assets/jsonld-D5RXTCJi.js AI (source-diff): jsonld library uses setImmediate polyfill with new Function; well-known pattern, not malware. ai
source-diff obfuscated-file:dist-ui/assets/AgentProfilePage-jB-v9soG.js AI (source-diff): Readable minified React component; not obfuscated malware. ai
source-diff obfuscated-file:dist-ui/assets/Operations-BC6Cv6cR.js AI (source-diff): Vite-bundled UI chunk; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/Network-d4igcZQ0.js AI (source-diff): Vite-bundled UI chunk; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/OnChainProvenanceCard-BL6ou6s9.js AI (source-diff): Vite-bundled UI chunk; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/renderer-3d-2EVDZII7-BTYEjwma.js AI (source-diff): Vite-bundled 3D renderer chunk; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/Settings-DXSjvx2a.js AI (source-diff): Vite-bundled UI settings chunk; minification expected. ai
source-diff obfuscated-file:dist-ui/assets/renderer-3d-2EVDZII7-CTUExXUn.js AI (source-diff): Vite-minified Three.js/3d renderer; standard build output. ai
source-diff obfuscated-file:dist-ui/assets/Settings-WaFKYtwQ.js AI (source-diff): Vite-minified UI bundle; standard build output. ai
source-diff obfuscated-file:dist-ui/assets/3d-force-graph-CcVMtgO4.js AI (source-diff): Standard Vite-minified 3d-force-graph bundle; not obfuscated malware. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): False positive in string template context within viem/abitype bundle. ai
semgrep semgrep:new-function-constructor AI (semgrep): jsonld library uses new Function() for context processing; documented behavior. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): Shiki syntax definition JSON for Batch files; not an actual DLL hijack command. ai
source-diff net-exec-file:dist-ui/assets/3d-force-graph-CcVMtgO4.js AI (source-diff): Network+exec pattern is D3/WebGL rendering library; no dropper behavior. ai
source-diff obfuscated-file:dist-ui/assets/Admin-DNNaF7rz.js AI (source-diff): Vite-minified UI bundle with abitype/viem code; legitimate frontend asset. ai
source-diff obfuscated-file:dist-ui/assets/AgentProfilePage-D2T_V6PG.js AI (source-diff): Vite-minified React component; readable DKG ontology URIs visible in sample. ai
source-diff obfuscated-file:dist-ui/assets/ccip-CDdHldzo.js AI (source-diff): Vite-minified viem CCIP read implementation; standard library code. ai
source-diff obfuscated-file:dist-ui/assets/index-2Gzrk1k3.js AI (source-diff): Main Vite bundle with React JSX runtime license header visible; legitimate. ai
source-diff obfuscated-file:dist-ui/assets/index-BrxEjqsW.js AI (source-diff): Vite-minified D3 selection/DOM code; standard visualization library. ai
source-diff net-exec-file:dist-ui/assets/index-BrxEjqsW.js AI (source-diff): D3 fetch+DOM manipulation; not a dropper pattern. ai
source-diff obfuscated-file:dist-ui/assets/index-W4n8cdTA.js AI (source-diff): Vite-minified frontend bundle; standard build output. ai
source-diff obfuscated-file:dist-ui/assets/jsonld-DkQdPwg5.js AI (source-diff): Vite-minified jsonld library with Digital Bazaar copyright; legitimate. ai
source-diff net-exec-file:dist-ui/assets/jsonld-DkQdPwg5.js AI (source-diff): jsonld library uses fetch for context loading; expected behavior. ai
source-diff obfuscated-file:dist-ui/assets/Network-C6MDsv2e.js AI (source-diff): Vite-minified UI bundle; standard build output. ai
source-diff obfuscated-file:dist-ui/assets/OnChainProvenanceCard-BbrU7jzL.js AI (source-diff): Vite-minified React component; standard build output. ai
source-diff obfuscated-file:dist-ui/assets/Operations-CCMDENBd.js AI (source-diff): Vite-minified UI bundle; standard build output. ai

Versions (showing 4 of 4)

Version Deps Published
10.0.2 22 / 17
10.0.1 13 / 17
10.0.0 13 / 17
0.0.1 3 / 19

v10.0.2

20 findings
HIGH New obfuscated file: dist-ui/assets/3d-force-graph-CcVMtgO4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist-ui/assets/3d-force-graph-CcVMtgO4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist-ui/assets/Admin-DNNaF7rz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/AgentProfilePage-D2T_V6PG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/ccip-CDdHldzo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/index-2Gzrk1k3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/index-BrxEjqsW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist-ui/assets/index-BrxEjqsW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist-ui/assets/index-W4n8cdTA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/jsonld-DkQdPwg5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist-ui/assets/jsonld-DkQdPwg5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist-ui/assets/Network-C6MDsv2e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/OnChainProvenanceCard-BbrU7jzL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/Operations-CCMDENBd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/renderer-3d-2EVDZII7-CTUExXUn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist-ui/assets/Settings-WaFKYtwQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH dll-hijacking-commands: dist-ui/assets/bat-BkioyH1T.js:1 semgrep

DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |

HIGH dll-hijacking-commands: dist-ui/assets/bat-BkioyH1T.js:1 semgrep

DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |

HIGH dll-hijacking-commands: dist-ui/assets/bat-BkioyH1T.js:1 semgrep

DLL side-loading command detected — potential DLL hijacking > 1 | const e=Object.freeze(JSON.parse('{"displayName":"Batch File","injections":{"L:meta.block.repeat.batchfile":{"patterns": 2 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.