← Home

@redocly/replay

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

romanhotsiyalawaradamaltmanmarshevskyyvolodymyr-rutskyislavikbezkorovainyi

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/replay-index-gs4LE2ro.js AI (source-diff): Bundled app code; benign network+exec pattern typical of SPA bundles. ai
npm-metadata no-description AI (npm-metadata): Known false positive for internal Redocly org packages. ai
source-diff obfuscated-file:dist/replay-index-BtkyH7jG.js AI (source-diff): Vite/Rollup bundled React app output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-BtkyH7jG.js AI (source-diff): Bundled app code; network+exec pattern is normal for a UI bundle, no malicious target. ai
source-diff obfuscated-file:dist/replay-index-ByJ9CDjb.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/replay-index-gs4LE2ro.js AI (source-diff): Bundled build output importing react/@redocly/theme, not obfuscation. ai
source-diff net-exec-file:dist/replay-index-BbgwrfFn.js AI (source-diff): Pattern-match on bundled SPA code, no concrete malicious behavior. ai
source-diff net-exec-file:dist/replay-index-WwrC-6Gc.js AI (source-diff): Bundled React/CJS output, no malicious behavior evident. ai
source-diff obfuscated-file:dist/replay-index-NZomfg-i.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/replay-index-WwrC-6Gc.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/replay-index-BbgwrfFn.js AI (source-diff): Bundled Vite/esbuild output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-C-2o3pWw.js AI (source-diff): Bundled app code with normal fetch/exec APIs, not a dropper. ai
source-diff net-exec-file:dist/replay-index-E5z9m196.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/replay-index-E5z9m196.js AI (source-diff): Bundled build output. ai
source-diff net-exec-file:dist/replay-index-DzHhiZhc.js AI (source-diff): Bundled React/UI code. ai
source-diff obfuscated-file:dist/replay-index-DzHhiZhc.js AI (source-diff): Bundled React/UI code. ai
source-diff net-exec-file:dist/replay-index-DMw5paEK.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/replay-index-DMw5paEK.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/replay-index-C-2o3pWw.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/replay-index-BC83BZLZ.js AI (source-diff): Minified vite/esbuild bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-WmDMPRXF.js AI (source-diff): Bundled app code. ai
source-diff obfuscated-file:dist/replay-index-WmDMPRXF.js AI (source-diff): Minified bundle output. ai
source-diff net-exec-file:dist/replay-index-DCh-sgSx.js AI (source-diff): Bundled app code. ai
source-diff obfuscated-file:dist/replay-index-DCh-sgSx.js AI (source-diff): Minified bundle output. ai
source-diff net-exec-file:dist/replay-index-CkdFdO0z.js AI (source-diff): Bundled app code. ai
source-diff obfuscated-file:dist/replay-index-CkdFdO0z.js AI (source-diff): Minified bundle output. ai
source-diff net-exec-file:dist/replay-index-BC83BZLZ.js AI (source-diff): Bundled React app code, network+eval patterns are library internals not a dropper. ai
source-diff obfuscated-file:dist/replay-index-CNA8w-F_.js AI (source-diff): Vite/esbuild bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-UU9ttWIq.js AI (source-diff): Bundled app code. ai
source-diff obfuscated-file:dist/replay-index-UU9ttWIq.js AI (source-diff): Bundled app code. ai
source-diff net-exec-file:dist/replay-index-DZKeaJ8u.js AI (source-diff): Bundled app code, no malicious destination. ai
source-diff obfuscated-file:dist/replay-index-DZKeaJ8u.js AI (source-diff): CJS bundle output of the same app. ai
source-diff net-exec-file:dist/replay-index-CYbvYpkU.js AI (source-diff): Bundled app code, no exfil target. ai
source-diff obfuscated-file:dist/replay-index-CYbvYpkU.js AI (source-diff): Bundled React/CodeMirror app code. ai
source-diff net-exec-file:dist/replay-index-CNA8w-F_.js AI (source-diff): Bundled app code (fetch+eval patterns from deps), not a dropper. ai
source-diff obfuscated-file:dist/replay-index-DBu78VZA.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-respect-run-CWl0J5uZ.js AI (source-diff): Bundled CLI output referencing local sibling chunk. ai
source-diff obfuscated-file:dist/replay-respect-run-CWl0J5uZ.js AI (source-diff): Bundled ESM CLI output, same pattern as sibling files. ai
source-diff net-exec-file:dist/replay-respect-run-Bw2hqa4a.js AI (source-diff): Bundled CLI runner code, local require chain only. ai
source-diff obfuscated-file:dist/replay-respect-run-Bw2hqa4a.js AI (source-diff): Bundled chalk-style CLI helper code, not obfuscation. ai
source-diff net-exec-file:dist/replay-index-GMR-4pxg.js AI (source-diff): Bundled UI code, no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/replay-index-GMR-4pxg.js AI (source-diff): Bundled ESM output from Vite build. ai
source-diff net-exec-file:dist/replay-index-DBu78VZA.js AI (source-diff): Bundled UI code referencing local chunks, no fetched payload execution. ai
source-diff net-exec-file:dist/replay-index-D9DnzDDB.js AI (source-diff): Bundled app code, benign. ai
source-diff net-exec-file:dist/replay-index-484u4S9t.js AI (source-diff): Bundled app code, no evidence of dropper/loader behavior. ai
source-diff obfuscated-file:dist/replay-index-C9mBzCPB.js AI (source-diff): Bundled React/CodeMirror UI code, minified not obfuscated. ai
source-diff net-exec-file:dist/replay-index-C9mBzCPB.js AI (source-diff): Bundled app code, no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/replay-index-CUhN6k9v.js AI (source-diff): Bundled output referencing sibling chunk, standard bundler split. ai
source-diff net-exec-file:dist/replay-index-CUhN6k9v.js AI (source-diff): Bundled app code, benign. ai
source-diff obfuscated-file:dist/replay-index-D9DnzDDB.js AI (source-diff): Bundled React/theme code, minified not obfuscated. ai
source-diff obfuscated-file:dist/replay-index-484u4S9t.js AI (source-diff): Bundled Vite/esbuild output, not true obfuscation. ai
phantom-deps phantom-dep:@redocly/vscode-json-languageservice AI (phantom-deps): Same-org scoped dependency; config-referenced; stable for this package. ai
phantom-deps phantom-dep:@uiw/codemirror-theme-material AI (phantom-deps): Config-referenced UI dependency; stable pattern for this package. ai
source-diff net-exec-file:dist/replay-index-BExnbqCh.js AI (source-diff): Bundler chunk with fetch+minified code, no malicious behavior found. ai
source-diff obfuscated-file:dist/replay-index-BKd-FZP1.js AI (source-diff): Minified CJS bundle, not obfuscation. ai
source-diff obfuscated-file:dist/replay-index-wIVtujmr.js AI (source-diff): Minified React/theme bundle, not obfuscation. ai
source-diff net-exec-file:dist/replay-index-wIVtujmr.js AI (source-diff): Bundled UI code; dynamic Function used for templating, not exfil. ai
source-diff obfuscated-file:dist/replay-index-BExnbqCh.js AI (source-diff): Bundled Vite/React build output, not true obfuscation. ai
source-diff obfuscated-file:dist/replay-index-DFpWzSPC.js AI (source-diff): Bundled vite build chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/replay-index-DbhbQ-kc.js AI (source-diff): Bundled vite/esbuild output (react/styled-components requires), not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-DbhbQ-kc.js AI (source-diff): Bundled app code; no fetched-binary-exec or credential exfil behavior present. ai
source-diff net-exec-file:dist/replay-index-DFpWzSPC.js AI (source-diff): Bundled app code; no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/replay-respect-run-CQM9_b08.js AI (source-diff): Bundled CLI chunk (chalk-style ANSI color code), minified not obfuscated. ai
source-diff net-exec-file:dist/replay-respect-run-CQM9_b08.js AI (source-diff): Bundled CLI runner code; env/process checks, not malicious exec. ai
source-diff obfuscated-file:dist/replay-respect-run-CWH1emdc.js AI (source-diff): Bundled build chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/replay-respect-run-CWH1emdc.js AI (source-diff): Bundled build chunk; no malicious behavior identified. ai
source-diff net-exec-file:dist/replay-index-BQhSATGV.js AI (source-diff): Minified React app bundle; net+exec heuristic on build output is a stable FP. ai
source-diff obfuscated-file:dist/replay-index-BQhSATGV.js AI (source-diff): Vite-minified CJS bundle output, not obfuscation. ai
source-diff net-exec-file:dist/replay-index-BsngDyks.js AI (source-diff): Minified React app bundle; net+exec heuristic on build output is a stable FP. ai
source-diff obfuscated-file:dist/replay-index-BsngDyks.js AI (source-diff): Vite-minified bundle output, not obfuscation; stable dist pattern. ai
bogus-package bogus-package AI (bogus-package): Internal Redocly component package, sparse metadata is normal for this monorepo pattern. ai
source-diff obfuscated-file:dist/replay-index-BcKmLvpW.js AI (source-diff): Bundled Vite/React build output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-DpQGPYrU.js AI (source-diff): Bundled UI code, benign network/exec patterns from React/CodeMirror libs. ai
source-diff obfuscated-file:dist/replay-index-DpQGPYrU.js AI (source-diff): Bundled Vite/React build output, not true obfuscation. ai
source-diff net-exec-file:dist/replay-index-BcKmLvpW.js AI (source-diff): Bundled UI code, benign network/exec patterns from React/CodeMirror libs. ai
source-diff net-exec-file:dist/replay-index-COdWKshd.js AI (source-diff): Bundled React app code, no dropper/loader behavior evident. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Monorepo config reference, not malicious. ai
source-diff net-exec-file:dist/replay-index-D6W9Obgo.js AI (source-diff): Bundled output, no malicious behavior evident. ai
source-diff obfuscated-file:dist/replay-index-D6W9Obgo.js AI (source-diff): Bundled CJS output of same app, not obfuscation. ai
source-diff obfuscated-file:dist/replay-index-COdWKshd.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
phantom-deps phantom-dep:@codemirror/lang-java AI (phantom-deps): CodeMirror language pack loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@tauri-apps/plugin-opener AI (phantom-deps): Tauri plugin loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@codemirror/lang-yaml AI (phantom-deps): CodeMirror language pack loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@codemirror/lang-python AI (phantom-deps): CodeMirror language pack loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@codemirror/lang-javascript AI (phantom-deps): CodeMirror language pack loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): AI SDK provider loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/google AI (phantom-deps): AI SDK provider loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): AI SDK provider loaded dynamically; stable pattern for this package. ai
phantom-deps phantom-dep:ulid AI (phantom-deps): Dynamically loaded via config; stable pattern for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Dynamically loaded via config; stable pattern for this package. ai
phantom-deps phantom-dep:idb AI (phantom-deps): Dynamically loaded via config; stable pattern for this package. ai
phantom-deps phantom-dep:@tauri-apps/api AI (phantom-deps): Bundled dist package; deps are compiled in, not directly imported. ai
phantom-deps phantom-dep:json-pointer AI (phantom-deps): Bundled dist package; deps are compiled in, not directly imported. ai
phantom-deps phantom-dep:path-browserify AI (phantom-deps): Bundled dist package; deps are compiled in, not directly imported. ai
phantom-deps phantom-dep:@hookstate/devtools AI (phantom-deps): Vite-bundled library; deps may not show direct imports in static analysis. ai
phantom-deps phantom-dep:@hookstate/localstored AI (phantom-deps): Vite-bundled library; deps may not show direct imports in static analysis. ai
phantom-deps phantom-dep:use-resize-observer AI (phantom-deps): Vite-bundled library; deps may not show direct imports in static analysis. ai
phantom-deps phantom-dep:@uiw/react-codemirror AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@tauri-apps/plugin-fs AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/lang-json AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/lang-html AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/lang-xml AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/state AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@lezer/highlight AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/view AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/lint AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:react-arborist AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:react-select AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:usehooks-ts AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:rc-tooltip AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:crypto-js AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Declared runtime dep in established @redocly org package; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:jszip AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:@codemirror/autocomplete AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai
phantom-deps phantom-dep:react-resizable-panels AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fails on bundled dist output. ai

Versions (showing 51 of 111)

View all versions
Version Deps Published
0.26.0 58 / 20
0.25.1 56 / 27
0.25.0 56 / 27
0.24.0 55 / 27
0.23.1 55 / 27
0.23.0 55 / 27
0.22.0 51 / 27
0.21.2 48 / 27
0.21.1 48 / 27
0.21.0 48 / 27
0.20.1 47 / 27
0.20.0 47 / 27
0.19.1 45 / 27
0.19.0 45 / 27
0.18.0 33 / 27
0.15.3 29 / 27
0.15.2 29 / 27
0.15.1 29 / 27
0.15.0 29 / 27
0.14.0 29 / 26
0.13.3 27 / 25
0.13.2 27 / 25
0.13.1 27 / 25
0.13.0 27 / 25
0.12.1 27 / 25
0.12.0 27 / 25
0.11.0 27 / 25
0.10.0 27 / 26
0.9.6 24 / 26
0.9.5 24 / 26
0.9.4 24 / 26
0.9.3 24 / 26
0.9.2 24 / 26
0.9.1 24 / 26
0.9.0 24 / 26
0.8.13 22 / 23
0.8.12 22 / 23
0.8.11 22 / 23
0.8.10 22 / 23
0.8.9 22 / 23
0.8.8 22 / 23
0.8.7 22 / 23
0.8.6 22 / 23
0.8.5 22 / 23
0.8.4 22 / 23
0.8.3 22 / 23
0.8.2 22 / 23
0.8.1 22 / 23
0.8.0 22 / 23
0.7.14 22 / 23
0.7.13 22 / 23

v0.26.0

8 findings
HIGH New obfuscated file: dist/replay-index-COdWKshd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-COdWKshd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-D6W9Obgo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-D6W9Obgo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-lint-graphql-CEtKQDNO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/replay-respect-run-CEYMtLaM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/replay-respect-run-o51nmiWP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.0

9 findings
HIGH New obfuscated file: dist/replay-index-DBu78VZA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DBu78VZA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-GMR-4pxg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-GMR-4pxg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-respect-run-Bw2hqa4a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-respect-run-Bw2hqa4a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-respect-run-CWl0J5uZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-respect-run-CWl0J5uZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.2

9 findings
HIGH New obfuscated file: dist/replay-index-C-2o3pWw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-C-2o3pWw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DMw5paEK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DMw5paEK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DzHhiZhc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DzHhiZhc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-E5z9m196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-E5z9m196.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.1

9 findings
HIGH New obfuscated file: dist/replay-index-BC83BZLZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BC83BZLZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-CkdFdO0z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-CkdFdO0z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DCh-sgSx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DCh-sgSx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-WmDMPRXF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-WmDMPRXF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

9 findings
HIGH New obfuscated file: dist/replay-index-BC83BZLZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BC83BZLZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-CkdFdO0z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-CkdFdO0z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DCh-sgSx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DCh-sgSx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-WmDMPRXF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-WmDMPRXF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.1

10 findings
HIGH Publisher changed: volodymyr-rutskyi → GitHub Actions (on 2026-01-13) provenance

This version was published by a different npm account than previous versions on 2026-01-13. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/replay-index-CNA8w-F_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-CNA8w-F_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-CYbvYpkU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-CYbvYpkU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DZKeaJ8u.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DZKeaJ8u.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-UU9ttWIq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-UU9ttWIq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

9 findings
HIGH New obfuscated file: dist/replay-index-484u4S9t.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-484u4S9t.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-C9mBzCPB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-C9mBzCPB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-CUhN6k9v.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-CUhN6k9v.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-D9DnzDDB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-D9DnzDDB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.1

6 findings
HIGH New obfuscated file: dist/replay-index-BbgwrfFn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BbgwrfFn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-NZomfg-i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/replay-index-WwrC-6Gc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-WwrC-6Gc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

6 findings
HIGH New obfuscated file: dist/replay-index-BtkyH7jG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BtkyH7jG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-ByJ9CDjb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/replay-index-gs4LE2ro.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-gs4LE2ro.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.0

6 findings
HIGH New obfuscated file: dist/replay-index-BExnbqCh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BExnbqCh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-BKd-FZP1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/replay-index-wIVtujmr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-wIVtujmr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.0

5 findings
HIGH New obfuscated file: dist/replay-index-BcKmLvpW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BcKmLvpW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-DpQGPYrU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-DpQGPYrU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

5 findings
HIGH New obfuscated file: dist/replay-index-BQhSATGV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BQhSATGV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/replay-index-BsngDyks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/replay-index-BsngDyks.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.7.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.