@recombine-ai/bosun
IDE for prompt engineers. Works best with [Recombine AI platform](https://recombine.ai?utm_source=github.bosun)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.CwOiRWmo.js | AI (source-diff): Vite/esbuild bundled client chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DC1Zz78t.js | AI (source-diff): Bundled SPA chunk with vite dynamic-import map, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/10.D2pJamM_.js | AI (source-diff): Vite/esbuild bundled client chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/17.tRxMrZSc.js | AI (source-diff): Vite/esbuild bundled client chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/18.h3m2E_FB.js | AI (source-diff): Vite/esbuild bundled client chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/18TZju1H.js | AI (source-diff): Svelte runtime bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DC1Zz78t.js | AI (source-diff): Vite/esbuild bundled client chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DISE-c5q.js | AI (source-diff): Vite-bundled SvelteKit client chunk; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DISE-c5q.js | AI (source-diff): WebSocket client code in bundled SvelteKit output, not a dropper. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.CsJyeODV.js | AI (source-diff): Bundled frontend code with fetch/dynamic import patterns typical of SPA routing, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.CsJyeODV.js | AI (source-diff): Bundled vite output; contains monaco-editor/popper libs, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DzqYKYUa.js | AI (source-diff): Vite/Svelte bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.DQJJVH8e.js | AI (source-diff): Vite bundled output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.CjsH6VcA.js | AI (source-diff): Vite bundled output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BFOPpRqC.js | AI (source-diff): Bundled framework chunk (Svelte internals). | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.CnyHXHFc.js | AI (source-diff): Vite entry bundle, explicitly labeled bundled artifact. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.C6l0CiJD.js | AI (source-diff): Vite bundle banner confirms build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.vrBdmqTE.js | AI (source-diff): Vite bundled client chunk, no malicious code found. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.4IvNSQft.js | AI (source-diff): SvelteKit/Vite bundled build output, no malicious payload. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.C6l0CiJD.js | AI (source-diff): Bundled SvelteKit client code; network+exec pattern is framework routing, not a dropper. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.BdQ4KFOK.js | AI (source-diff): Bundled Vite chunk, no concrete malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.ByTs9mVS.js | AI (source-diff): Vite-bundled SvelteKit client output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/VQG4jNzT.js | AI (source-diff): SvelteKit internal chunk, minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.aQDtFLfd.js | AI (source-diff): Vite entry bundle, explicitly labeled bundled artifact. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.aTGX3G73.js | AI (source-diff): Vite-bundled output. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.ByTs9mVS.js | AI (source-diff): Same bundled client file; fetch/exec patterns are normal SvelteKit runtime code. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.Be6ngYER.js | AI (source-diff): Vite-bundled SvelteKit client output; bundler banner present, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.Be6ngYER.js | AI (source-diff): Bundled client chunk with WebSocket client code, not a dropper. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.Bhgshf0y.js | AI (source-diff): Bundled app code (websocket client), no exfil behavior found. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.Bhgshf0y.js | AI (source-diff): Vite-bundled SvelteKit client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.y0kBiBeI.js | AI (source-diff): Vite build output for SvelteKit app; minified, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.5rylTC5r.js | AI (source-diff): Vite bundle containing monaco-editor/popperjs; bundler banner present, no malicious payload. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.5rylTC5r.js | AI (source-diff): Network+eval pattern is from bundled libraries (popper/monaco), not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.CJ_bsERC.js | AI (source-diff): Vite-bundled entry, standard bundler banner. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Established libraries consistent with app's editor/timeline/CSV features. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/7.BYKTckLf.js | AI (source-diff): Vite-bundled output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.DBodeuqK.js | AI (source-diff): Vite-bundled output. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.P49VQzwV.js | AI (source-diff): Bundled client code with fetch/dynamic import, standard for SvelteKit app, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.P49VQzwV.js | AI (source-diff): Vite-bundled SvelteKit client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.B8thI4e5.js | AI (source-diff): Vite bundle chunk. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.2gTriI_k.js | AI (source-diff): Bundled SvelteKit page code, network+exec is framework runtime not exfil. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.CiM16g8I.js | AI (source-diff): Vite bundle chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.oTjMxsRk.js | AI (source-diff): Vite entry bundle, explicitly labeled bundler output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/CNhN10hv.js | AI (source-diff): Vite bundle chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/D6SJvIkF.js | AI (source-diff): Large vendored monaco-editor chunk, bundler banner present. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.BziS38Er.js | AI (source-diff): Vite-bundled SvelteKit client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.2gTriI_k.js | AI (source-diff): Vite-bundled output; bundler banner present, no malicious behavior shown. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.DgNr1qo_.js | AI (source-diff): Bundled frontend chunk, network+eval calls are Monaco worker/fetch APIs, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.DgNr1qo_.js | AI (source-diff): Vite-bundled Monaco/app chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/3.CXpLtxG2.js | AI (source-diff): Bundled SvelteKit chunk; dynamic import machinery, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.CXpLtxG2.js | AI (source-diff): Vite/Svelte bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.SsrvuMXV.js | AI (source-diff): Vite/monaco bundle, bundler banner present. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.BO0WBJz3.js | AI (source-diff): Vite bundle output for SvelteKit UI, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.SsrvuMXV.js | AI (source-diff): Bundled monaco-editor client code, no exfil target. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/4PztAao_.js | AI (source-diff): Monaco-editor bundled language chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.DRJDjScL.js | AI (source-diff): Vite bundle output (monaco/sveltekit build), not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.DY8rkawO.js | AI (source-diff): Vite entry bundle, explicitly labeled bundled artifact. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.tSLEKq4V.js | AI (source-diff): Bundled Svelte component output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/6Eq_BzHM.js | AI (source-diff): Monaco editor bundle. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.DeC8KwBH.js | AI (source-diff): Vite bundle output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DBIsVxAx.js | AI (source-diff): Bundled Svelte component output. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.DRJDjScL.js | AI (source-diff): Bundled client app code, network+eval pattern is normal SPA runtime code. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/DBddxTGL.js | AI (source-diff): SvelteKit runtime chunk, minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/11.Cb657Pjj.js | AI (source-diff): Vite/Svelte bundled client output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.Gs4InE6Y.js | AI (source-diff): Vite/Svelte bundled client output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.wtO9K4Q5.js | AI (source-diff): Vite bundle banner present; standard build output. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.wtO9K4Q5.js | AI (source-diff): Standard Vite/SvelteKit fetch wrapper in bundled client code, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.ClVyPX2B.js | AI (source-diff): Vite bundled client output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.BXj3LA7H.js | AI (source-diff): Vite bundler entry file, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DyfyeFv9.js | AI (source-diff): Bundled SvelteKit client code, no concrete malicious behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DyfyeFv9.js | AI (source-diff): Vite-bundled client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.IJ8N1LYx.js | AI (source-diff): Vite bundle output for SvelteKit app; no malicious payload in sample. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/chunks/B5CoBEt2.js | AI (source-diff): Bundled build output, not standalone loader malware. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/B5CoBEt2.js | AI (source-diff): Large vite chunk, consistent with bundled monaco-editor deps. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.IJ8N1LYx.js | AI (source-diff): Bundled client code (Monaco/websocket editor), not a dropper. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.BbzjrdMu.js | AI (source-diff): WebSocket client code in bundled SvelteKit app, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.BbzjrdMu.js | AI (source-diff): Vite-bundled SvelteKit client chunk; bundler banner present, no malicious behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BfHUxT3G.js | AI (source-diff): Monaco editor bundle, standard minified vendor code. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.pYR7L1PM.js | AI (source-diff): Vite-bundled client chunk, bundler banner present; no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.pYR7L1PM.js | AI (source-diff): WebSocket client code in bundled SvelteKit app, not a dropper. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.BmMuB33m.js | AI (source-diff): Bundled frontend code with normal fetch/WS client, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.BmMuB33m.js | AI (source-diff): Vite-bundled SvelteKit client chunk; minified, not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.Dj49wycs.js | AI (source-diff): Standard Vite dynamic chunk loader, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BP5_MbBx.js | AI (source-diff): SvelteKit/Vite bundled chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/5GeD9mgh.js | AI (source-diff): Monaco-editor bundled language module, minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.Dj49wycs.js | AI (source-diff): Vite bundler output (__vite__mapDeps banner); minified, not obfuscated. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.DmNYVNpM.js | AI (source-diff): Vite bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.DOQjI9N3.js | AI (source-diff): Vite bundled SvelteKit route chunk. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.DOQjI9N3.js | AI (source-diff): Bundled client route code calling own tRPC API, not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/2bC5Sd4A.js | AI (source-diff): Vite-bundled monaco-editor/runtime chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.Dcr2A6Tb.js | AI (source-diff): Same bundled Vite chunk; no fetched-binary or exfil behavior present. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.brwSC-m1.js | AI (source-diff): Vite-bundled build chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.BrdVgLBj.js | AI (source-diff): Vite-bundled build chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.BrdVgLBj.js | AI (source-diff): Bundled Svelte app code with fetch calls; no fetched-binary execution behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.Bganupc1.js | AI (source-diff): Vite-bundled build chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.24Pm3H0k.js | AI (source-diff): Vite entry bundle, bundler banner present. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/soKHomD-.js | AI (source-diff): Bundled build chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.CzXkpJlv.js | AI (source-diff): Vite-bundled Svelte component chunk. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): Used indirectly via config/backend, common in this app's stack. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DfspGIrH.js | AI (source-diff): Vite build output for SvelteKit page bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.Bq8mXhG_.js | AI (source-diff): Bundled SvelteKit router code wrapping window.fetch, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.Bq8mXhG_.js | AI (source-diff): Vite bundled client chunk; banner confirms bundler artifact. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/kGq7IGZN.js | AI (source-diff): Bundled Vite chunk, confirmed banner. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/DOlTVmh8.js | AI (source-diff): Bundled Vite chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/D6OLb1p5.js | AI (source-diff): Bundled Vite chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/Bry13MUx.js | AI (source-diff): Bundled Vite chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BKwadjSB.js | AI (source-diff): SvelteKit runtime chunk, standard bundled output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BgfFbz8o.js | AI (source-diff): Bundled chunk containing mock call-transcript fixture data, not malicious. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.DMasDG54.js | AI (source-diff): Vite entry bundle, confirmed bundler banner. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.BRDSkTxr.js | AI (source-diff): Vite bundled output; content is UI component code with mock demo data. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/6.CCx0We7V.js | AI (source-diff): Vite bundled output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/4.BYlkoyF7.js | AI (source-diff): Vite-bundled SvelteKit client output; bundler banner confirms build artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/4.BYlkoyF7.js | AI (source-diff): Bundled frontend chunk; no fetched/executed remote payload, just minified app code. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DniQTiGZ.js | AI (source-diff): Vite bundler banner present; standard chunked build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/_yZg6Sf-.js | AI (source-diff): Vite/Svelte bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/-g1l5aoS.js | AI (source-diff): Vite/Svelte bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/10.dE-XOJgk.js | AI (source-diff): Vite bundler banner present; standard chunked build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/17.BwzZwCD0.js | AI (source-diff): Vite/Svelte bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/18.BUMDuaQF.js | AI (source-diff): Vite/Svelte bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DniQTiGZ.js | AI (source-diff): Bundled frontend chunk; no actual dropper/loader behavior, just fetch/import in app code. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.BIO1e-qq.js | AI (source-diff): Vite/Svelte bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DX9U9zLg.js | AI (source-diff): Vite bundler banner present; minified build chunk. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DX9U9zLg.js | AI (source-diff): WebSocket client code in bundled SvelteKit chunk, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.Bh8il5iy.js | AI (source-diff): Bundled Svelte component output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/7.CBPrYfFp.js | AI (source-diff): Bundled Svelte component output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/8.4NTWYv4c.js | AI (source-diff): Vite bundled chunk (iconify library). | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.jP0Pyfdy.js | AI (source-diff): Vite entry bundle, explicitly labeled bundler output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/B3K88SyC.js | AI (source-diff): Bundled Svelte UI chunk. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BGEE3mf3.js | AI (source-diff): Bundled build chunk, consistent with sibling files. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BH7VBnJ7.js | AI (source-diff): Bundled build chunk, consistent with sibling files. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change reflects CI/CD provenance improvement, not compromise. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/14.I-eiMWQu.js | AI (source-diff): Vite/SvelteKit bundled client output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/18.B8hhkZZh.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DZ1cMXf3.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/BqYZT6mz.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/DgnCUaz1.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DZ1cMXf3.js | AI (source-diff): SvelteKit client bundle; network calls are fetch API and dynamic imports, not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.CCm10CUg.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.Td5mdQc9.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.CE1yZowM.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/17.BTYNQV25.js | AI (source-diff): Standard SvelteKit/Vite minified build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.Bpgxjy-s.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.CWbDFdJc.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.DuwVz5hs.js | AI (source-diff): Browser fetch + dynamic import in SvelteKit client bundle; normal SPA pattern, not dropper malware. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.DuwVz5hs.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/18.D6rkjSXS.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/17.Bn7AdwZ5.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/0e_4hQ6g.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/yPd1epTY.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.B5srlcvO.js | AI (source-diff): Standard Vite/SvelteKit minified build output; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/CD54oo-Q.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): SvelteKit build generates many content-hashed chunk files per build; expected for this package type. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/chunks/CAnrK2Rl.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/entry/app.DoUqDuhT.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/9.DatTKw7a.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/3.CCDyeAHw.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | net-exec-file:build/client/_app/immutable/nodes/2.COX-RTiI.js | AI (source-diff): Network calls are navigator.clipboard; dynamic patterns are Svelte runtime boilerplate, not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/2.COX-RTiI.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/18.BV7lLFx7.js | AI (source-diff): Standard SvelteKit/Vite minified build output. | ai | |
| source-diff | obfuscated-file:build/client/_app/immutable/nodes/17.CgqWHP0Y.js | AI (source-diff): Standard SvelteKit/Vite minified build output; content-hash filenames are normal for this package. | ai | |
| phantom-deps | phantom-dep:googleapis | AI (phantom-deps): Backend dependency referenced in config but not directly imported in CLI entry. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/typography | AI (phantom-deps): Tailwind plugin; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/forms | AI (phantom-deps): Tailwind plugin; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:svelte-dnd-action | AI (phantom-deps): Svelte UI library; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:@types/papaparse | AI (phantom-deps): Type definitions for frontend library; not expected to be directly imported. | ai | |
| phantom-deps | phantom-dep:@iconify/svelte | AI (phantom-deps): Svelte icon library; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:@popperjs/core | AI (phantom-deps): Frontend UI dependency; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:monaco-editor | AI (phantom-deps): Frontend editor component; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:vis-timeline | AI (phantom-deps): Frontend visualization library; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): CSS framework; referenced in config files, not CLI. | ai | |
| phantom-deps | phantom-dep:xss | AI (phantom-deps): Frontend dependency declared in package.json but not imported in CLI entry point. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): CLI tool spreading process.env into child process spawn — standard pattern, not exfiltration. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Frontend dependency declared in package.json but not imported in CLI entry point. | ai | |
| phantom-deps | phantom-dep:tsx | AI (phantom-deps): SvelteKit project; tsx is a build/dev tool referenced in config, not directly imported in CLI. | ai | |
| phantom-deps | phantom-dep:bits-ui | AI (phantom-deps): Svelte UI component library; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:vis-data | AI (phantom-deps): Frontend visualization library; used in frontend, not CLI. | ai | |
| phantom-deps | phantom-dep:papaparse | AI (phantom-deps): Frontend CSV library; used in frontend, not CLI. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 0.11.1 | 32 / 26 | |
| 0.10.1 | 32 / 26 | |
| 0.10.0 | 32 / 26 | |
| 0.9.1 | 32 / 26 | |
| 0.9.0 | 32 / 26 | |
| 0.8.3 | 30 / 26 | |
| 0.8.2 | 30 / 26 | |
| 0.8.1 | 30 / 24 | |
| 0.8.0 | 30 / 24 | |
| 0.7.0 | 30 / 24 | |
| 0.6.1 | 30 / 24 | |
| 0.6.0 | 30 / 24 | |
| 0.5.1 | 30 / 24 | |
| 0.4.1 | 26 / 24 | |
| 0.4.0 | 26 / 24 | |
| 0.3.12 | 26 / 24 | |
| 0.3.11 | 26 / 24 | |
| 0.3.10 | 26 / 24 | |
| 0.3.9 | 26 / 24 | |
| 0.3.7 | 25 / 23 | |
| 0.3.6 | 25 / 23 | |
| 0.3.5 | 25 / 23 | |
| 0.3.4 | 25 / 23 | |
| 0.3.2 | 25 / 23 | |
| 0.3.1 | 25 / 23 | |
| 0.3.0 | 25 / 23 | |
| 0.2.10 | 25 / 23 | |
| 0.2.9 | 25 / 23 | |
| 0.2.8 | 25 / 23 | |
| 0.2.7 | 25 / 23 | |
| 0.2.6 | 25 / 23 | |
| 0.2.5 | 25 / 23 | |
| 0.2.4 | 25 / 23 | |
| 0.2.3 | 25 / 23 | |
| 0.2.2 | 25 / 23 | |
| 0.2.1 | 25 / 23 | |
| 0.2.0 | 25 / 23 |
v0.11.1
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
13 findingsThis version was published by a different npm account than previous versions on 2026-03-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
13 findingsThis version was published by a different npm account than previous versions on 2026-03-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
13 findingsThis version was published by a different npm account than previous versions on 2026-03-30. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
12 findingsThis version was published by a different npm account than previous versions on 2026-03-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
10 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
10 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.12
14 findingsThis version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.11
14 findingsThis version was published by a different npm account than previous versions on 2026-02-26. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.10
13 findingsThis version was published by a different npm account than previous versions on 2026-02-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.9
12 findingsThis version was published by a different npm account than previous versions on 2026-02-20. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.7
16 findingsThis version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.6
15 findingsThis version was published by a different npm account than previous versions on 2026-02-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.5
16 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.4
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
19 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
20 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
21 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.10
19 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.9
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.8
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.7
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.6
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.5
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.4
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.