← Home

@paypal/messaging-components

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sdk-integrations-npmsiokedpaypal-sdksbraintreejfurmanravishekhar00gregjopamnicptelizabethmvnbierdemanremotevisionrygilbert_paypalbesierrarosman21wsbrunsonyanisimov_paypalavathaluringseguindustijonessunnypatelcsjcsjcsjbywoodppeelenizsupremarimbrian-paypalcnallamgabrielg-paypalaugreer8jdutterer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Bundled SDK code, benign network+exec patterns from normal webpack runtime. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled dist output, not obfuscation; consistent with every prior release. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): SDK legitimately performs network calls + module loader eval, standard bundle pattern. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled minified build output, not true obfuscation. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled minified output, not true obfuscation. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Bundled SDK code with fetch+module-loader, not a dropper. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Bundled analytics/API calls in first-party SDK, not a dropper pattern. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled minified output, not true obfuscation; standard for this build pipeline. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Bundled network/fetch calls in SDK code, not a dropper pattern. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled dist output, not true obfuscation; consistent with prior releases. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Standard bundler network+module-loader pattern for this SDK, not dropper behavior. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Webpack-bundled minified dist output, not true obfuscation. ai
source-diff obfuscated-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Standard webpack-minified bundle, not true obfuscation. ai
source-diff net-exec-file:dist/bizcomponents/js/versioned/[email protected] AI (source-diff): Bundled SDK code with normal network calls, no malicious behavior evidenced. ai
maintainer-change maintainer-removed AI (maintainer-change): Org-managed CI/CD publishing; maintainer churn not indicative of takeover. ai
source-diff large-new-source-files AI (source-diff): Expected new dist bundles per release cycle for this SDK. ai
source-diff bulk-net-exec-files:dist AI (source-diff): Webpack bundle heuristic false positive on bundled dist output. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Routine webpack build output, minified not obfuscated. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used only for inline DOM event handler attributes in elements.js; controlled input, not arbitrary user-supplied code. ai
phantom-deps phantom-dep:@paypal/sdk-logos AI (phantom-deps): Same-org PayPal dependency; declared as runtime dep, likely used transitively or in build output. ai

Versions (showing 15 of 15)

Version Deps Published
1.90.1 10 / 51
1.89.0 10 / 50
1.87.0 10 / 50
1.86.0 10 / 50
1.85.0 10 / 50
1.84.1 10 / 50
1.83.0 10 / 50
1.82.0 10 / 50
1.80.0 10 / 50
1.79.0 10 / 50
1.78.0 10 / 50
1.77.1 10 / 50
1.77.0 10 / 50
1.76.1 10 / 50
1.76.0 11 / 50

v1.90.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.80.0

31 findings
HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.79.0

31 findings
HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.78.0

31 findings
HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.77.1

31 findings
HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.77.0

31 findings
HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/js/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/sandbox/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bizcomponents/stage/versioned/[email protected] source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.76.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.76.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.