← Home

@rsdoctor/client

This package is the Rsdoctor reporting platform.

55
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yifancongchenjiahan

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/resource/js/index.7997b81b6e.js AI (source-diff): rspack-bundled React dist output; minified, not obfuscated. ai
source-diff net-exec-file:dist/resource/js/index.7997b81b6e.js AI (source-diff): Browser DOM/createRoot in bundled UI; first-party assets only. ai
source-diff net-exec-file:dist/resource/js/diff.e2c900a07a.js AI (source-diff): Browser DOM/createRoot in bundled UI; first-party assets only. ai
source-diff obfuscated-file:dist/resource/js/diff.e2c900a07a.js AI (source-diff): rspack-bundled React dist output; minified, not obfuscated. ai
source-diff obfuscated-file:dist/resource/js/226.b4954a9cff.js AI (source-diff): rspack-bundled React dist output; minified, not obfuscated. ai
source-diff net-exec-file:dist/resource/js/diff.972c8afa.js AI (source-diff): App diff-view bundle; minified webpack chunk. ai
source-diff net-exec-file:dist/resource/js/index.1c12c054.js AI (source-diff): App index bundle; minified webpack output. ai
source-diff net-exec-file:dist/resource/js/116.e9b0bfeb.js AI (source-diff): Browser fetch + React runtime in bundled UI; no exfil target. ai
source-diff net-exec-file:dist/resource/js/index.f504900b.js AI (source-diff): Browser fetch + React runtime, benign. ai
source-diff obfuscated-file:dist/resource/js/index.f504900b.js AI (source-diff): Webpack-bundled frontend entry. ai
source-diff net-exec-file:dist/resource/js/diff.e4f3458a.js AI (source-diff): Browser fetch + React runtime, benign. ai
source-diff obfuscated-file:dist/resource/js/diff.e4f3458a.js AI (source-diff): Webpack-bundled frontend entry. ai
source-diff obfuscated-file:dist/resource/js/904.e574a404.js AI (source-diff): Webpack-bundled frontend asset. ai
source-diff obfuscated-file:dist/resource/js/116.e9b0bfeb.js AI (source-diff): Webpack-bundled frontend asset; minified not obfuscated. ai
source-diff net-exec-file:dist/resource/js/375.29108e01.js AI (source-diff): Bundled UI code; no exfil destination, benign build output. ai
source-diff obfuscated-file:dist/resource/js/vender.08a5ec82.js AI (source-diff): Webpack vendor bundle; minified build output. ai
source-diff obfuscated-file:dist/resource/js/rc-0.5662d149.js AI (source-diff): Webpack-bundled rc-* UI libs; minified build output. ai
source-diff net-exec-file:dist/resource/js/index.2c346ce0.js AI (source-diff): First-party favicon link injection; benign bundled UI. ai
source-diff obfuscated-file:dist/resource/js/index.2c346ce0.js AI (source-diff): Webpack entry bundle; minified build output. ai
source-diff net-exec-file:dist/resource/js/diff.d7e8e4b5.js AI (source-diff): DOM favicon link injection to first-party assets.rspack.rs; benign. ai
source-diff obfuscated-file:dist/resource/js/diff.d7e8e4b5.js AI (source-diff): Webpack entry bundle; minified build output. ai
source-diff obfuscated-file:dist/resource/js/611.00341793.js AI (source-diff): Webpack-bundled icon UI; minified build output. ai
source-diff obfuscated-file:dist/resource/js/538.26a222ec.js AI (source-diff): Webpack-bundled app UI; minified build output. ai
source-diff obfuscated-file:dist/resource/js/510.e39f3818.js AI (source-diff): Webpack-bundled react-slick UI; minified build output. ai
source-diff obfuscated-file:dist/resource/js/375.29108e01.js AI (source-diff): Webpack-bundled browser asset; minified not obfuscated, stable for this package. ai
source-diff net-exec-file:dist/resource/js/diff.f47d35f1.js AI (source-diff): React createRoot + DOM link injection in browser bundle, no fetched code execution ai
source-diff obfuscated-file:dist/resource/js/vender.964dfc5c.js AI (source-diff): webpack vendor chunk, minified ai
source-diff obfuscated-file:dist/resource/js/rc-0.bd9999ac.js AI (source-diff): webpack rc-* vendor chunk, minified ai
source-diff obfuscated-file:dist/resource/js/246.d2c7c8d3.js AI (source-diff): webpack chunk (antd icons), minified ai
source-diff obfuscated-file:dist/resource/js/react.3dfe4388.js AI (source-diff): React vendor bundle, minified ai
source-diff obfuscated-file:dist/resource/js/index.fdf47698.js AI (source-diff): webpack SPA entry bundle, minified ai
source-diff obfuscated-file:dist/resource/js/diff.f47d35f1.js AI (source-diff): webpack SPA bundle, minified ai
source-diff net-exec-file:dist/resource/js/index.fdf47698.js AI (source-diff): React SPA bootstrap bundle; benign network/DOM patterns ai
source-diff obfuscated-file:dist/resource/js/159.bca660e6.js AI (source-diff): webpack browser bundle in official Rsdoctor UI; minified not obfuscated ai
source-diff net-exec-file:dist/resource/js/384.d4e59acc.js AI (source-diff): bundled webpack chunk, no fetched-binary exec; false positive on build output. ai
source-diff net-exec-file:dist/resource/js/react.3dfe4388.js AI (source-diff): webpack-bundled react vendor chunk; false positive. ai
source-diff net-exec-file:dist/resource/js/index.d0420c7a.js AI (source-diff): bundled UI entry; DOM/API calls to own service, not exfil. ai
source-diff net-exec-file:dist/resource/js/diff.48b74bd1.js AI (source-diff): DOM createElement + own-SDK API calls in bundled UI; benign. ai
source-diff obfuscated-file:dist/resource/js/384.d4e59acc.js AI (source-diff): webpack-bundled antd color palette code; minified build output. ai
source-diff obfuscated-file:dist/resource/js/vender.158198ea.js AI (source-diff): Webpack-bundled browser vendor chunk; minified build output, recurs every release. ai
source-diff net-exec-file:dist/resource/js/864.3ff7582d41.js AI (source-diff): Minified bundle heuristic; no hostile net+exec behavior. ai
source-diff obfuscated-file:dist/resource/js/864.3ff7582d41.js AI (source-diff): rspack-bundled webpack chunk (minified), not obfuscation. ai
source-diff net-exec-file:dist/resource/js/react.93256790.js AI (source-diff): React vendor bundle; false-positive net-exec on minified output. ai
source-diff net-exec-file:dist/resource/js/410.a54d7b65.js AI (source-diff): antd color bundle; net/exec pattern-match on minified vendor code, benign. ai
source-diff obfuscated-file:dist/resource/js/118.35589783.js AI (source-diff): Webpack vendor bundle; minified not obfuscated. ai
source-diff net-exec-file:dist/resource/js/index.28a83613.js AI (source-diff): Bundled entry; net+eval inherent to webpack runtime. ai
source-diff obfuscated-file:dist/resource/js/index.28a83613.js AI (source-diff): Webpack entry bundle; minified build output. ai
source-diff net-exec-file:dist/resource/js/diff.81f1287f.js AI (source-diff): Bundled diff viewer; net+eval inherent to webpack runtime, no hostile target. ai
source-diff obfuscated-file:dist/resource/js/diff.81f1287f.js AI (source-diff): Webpack bundle of diff viewer; minified build output. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.624aa7d5.js AI (source-diff): Webpack bundle of antd icon SVG data; minified build output. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.51693c58.js AI (source-diff): Webpack bundle of antd rate; minified build output. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.0aa20e29.js AI (source-diff): Webpack bundle of antd modal; minified build output. ai
source-diff obfuscated-file:dist/resource/js/349.1caba575.js AI (source-diff): Webpack bundle of ant-design-icons; minified build output. ai
source-diff obfuscated-file:dist/resource/js/682.ad96e5a1.js AI (source-diff): Webpack bundle of client UI; minified build output. ai
source-diff obfuscated-file:dist/resource/js/vender.8fa54b46.js AI (source-diff): Webpack vendor bundle; minified build output. ai
source-diff obfuscated-file:dist/resource/js/react.ced7dd51.js AI (source-diff): Webpack bundle of react runtime; minified build output. ai
source-diff obfuscated-file:dist/resource/js/rc-1.06a42c11.js AI (source-diff): Webpack bundle of rc-* components; minified build output. ai
source-diff obfuscated-file:dist/resource/js/rc-0.a0e85196.js AI (source-diff): Webpack bundle of rc-* components; minified build output. ai
source-diff obfuscated-file:dist/resource/js/197.aa320ba5.js AI (source-diff): Webpack-bundled ant-design color palette; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/vender.4a6fee86.js AI (source-diff): Bundled vendor chunk; minified build output. ai
source-diff net-exec-file:dist/resource/js/react.72d3d85b.js AI (source-diff): React vendor bundle; benign browser code. ai
source-diff obfuscated-file:dist/resource/js/react.72d3d85b.js AI (source-diff): Bundled React vendor; minified build output. ai
source-diff obfuscated-file:dist/resource/js/rc-0.1aa34d68.js AI (source-diff): Bundled rc-* vendor; minified build output. ai
source-diff net-exec-file:dist/resource/js/index.3304dad7.js AI (source-diff): createRoot/DOM ops; benign browser bundle. ai
source-diff obfuscated-file:dist/resource/js/index.3304dad7.js AI (source-diff): Bundled app entry; minified webpack output. ai
source-diff net-exec-file:dist/resource/js/diff.960a19ea.js AI (source-diff): createRoot/link injection to rspack.rs assets; benign browser bundle. ai
source-diff obfuscated-file:dist/resource/js/diff.960a19ea.js AI (source-diff): Bundled app entry; minified webpack output. ai
source-diff obfuscated-file:dist/resource/js/883.0a0d6fad.js AI (source-diff): Bundled ant-design icons; minified build output. ai
source-diff obfuscated-file:dist/resource/js/791.5f557611.js AI (source-diff): Bundled app UI; minified webpack chunk. ai
source-diff obfuscated-file:dist/resource/js/610.d58c44f0.js AI (source-diff): Bundled slick-carousel; minified build output. ai
source-diff net-exec-file:dist/resource/js/197.aa320ba5.js AI (source-diff): Bundled browser UI code; DOM ops not code-exec dropper. ai
source-diff obfuscated-file:dist/resource/js/512.c80dd09b.js AI (source-diff): Webpack-bundled frontend chunk; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/resource/js/732.68bd2b07.js AI (source-diff): Bundled React app code; net+exec pattern is framework runtime, no hostile target. ai
source-diff net-exec-file:dist/resource/js/react.ced7dd51.js AI (source-diff): Bundled React vendor chunk; benign framework code. ai
source-diff obfuscated-file:dist/resource/js/732.68bd2b07.js AI (source-diff): Webpack-bundled antd color module; minified vendor output, not obfuscation. ai
source-diff net-exec-file:dist/resource/js/205.9c1c308a.js AI (source-diff): Bundled antd chunk; net+eval patterns are minifier artifacts, no hostile target. ai
source-diff obfuscated-file:dist/resource/js/205.9c1c308a.js AI (source-diff): Webpack-bundled browser asset; minified not obfuscated. ai
source-diff net-exec-file:dist/resource/js/483.925ce01f.js AI (source-diff): Bundled antd color lib; net+eval are false positives in minified web UI bundle. ai
source-diff net-exec-file:dist/resource/js/react.5d8fd297.js AI (source-diff): Bundled react vendor chunk; net+eval FP in minified output. ai
source-diff obfuscated-file:dist/resource/js/483.925ce01f.js AI (source-diff): Webpack-bundled vendor chunk; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/resource/js/react.f85b41a1.js AI (source-diff): React vendor bundle, benign. ai
source-diff obfuscated-file:dist/resource/js/react.f85b41a1.js AI (source-diff): Minified React vendor bundle. ai
source-diff net-exec-file:dist/resource/js/index.17450227.js AI (source-diff): Bundled app entry, benign. ai
source-diff obfuscated-file:dist/resource/js/index.17450227.js AI (source-diff): esbuild-bundled app entry; minified build output. ai
source-diff net-exec-file:dist/resource/js/751.3fa00fdf.js AI (source-diff): Bundled browser asset, no hostile destination. ai
source-diff obfuscated-file:dist/resource/js/751.3fa00fdf.js AI (source-diff): Webpack-bundled antd vendor asset; minified not obfuscated. ai
source-diff obfuscated-file:dist/resource/js/751.6608c443.js AI (source-diff): webpack-bundled browser asset (antd fast-color), not obfuscation. ai
source-diff net-exec-file:dist/resource/js/vender.7010d5f5.js AI (source-diff): Bundled vendor libs; benign. ai
source-diff obfuscated-file:dist/resource/js/vender.7010d5f5.js AI (source-diff): Bundled vendor libs (lodash). ai
source-diff net-exec-file:dist/resource/js/react.e3c21fa0.js AI (source-diff): Bundled React runtime; benign. ai
source-diff obfuscated-file:dist/resource/js/react.e3c21fa0.js AI (source-diff): Bundled React runtime. ai
source-diff net-exec-file:dist/resource/js/index.66a99a77.js AI (source-diff): Minified app bundle; benign. ai
source-diff obfuscated-file:dist/resource/js/index.66a99a77.js AI (source-diff): esbuild-bundled app code for rsdoctor client UI. ai
source-diff net-exec-file:dist/resource/js/751.6608c443.js AI (source-diff): Minified browser bundle; net+eval patterns are library code, no malicious target. ai
source-diff net-exec-file:dist/resource/js/154.ff7cbe5fa3.js AI (source-diff): Heuristic fires on normal minified bundle; no hostile target. ai
source-diff obfuscated-file:dist/resource/js/154.ff7cbe5fa3.js AI (source-diff): rspack-bundled web UI asset; minified not obfuscated. ai
source-diff obfuscated-file:dist/resource/js/diff.b164bb1239.js AI (source-diff): Rspack-bundled React UI chunk; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/resource/js/index.d69991f975.js AI (source-diff): Browser-side React app; network+exec patterns are fetch API and dynamic imports in bundled UI. ai
source-diff net-exec-file:dist/resource/js/diff.b164bb1239.js AI (source-diff): Browser-side React app; network+exec patterns are fetch API and dynamic imports in bundled UI. ai
source-diff obfuscated-file:dist/resource/js/index.d69991f975.js AI (source-diff): Rspack-bundled React UI chunk; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/668.5625ee4138.js AI (source-diff): Rspack bundle output for React UI client; minified build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.3388a59c42.js AI (source-diff): Bundled Ant Design icon SVG data; expected minified output. ai
source-diff net-exec-file:dist/resource/js/index.225c62a776.js AI (source-diff): Browser-side React app; fetch + dynamic patterns are normal for SPA bundles. ai
source-diff net-exec-file:dist/resource/js/diff.35abbf717e.js AI (source-diff): Browser-side React app; fetch + dynamic patterns are normal for SPA bundles. ai
source-diff obfuscated-file:dist/resource/js/index.225c62a776.js AI (source-diff): Minified rspack browser bundle; standard build output. ai
source-diff obfuscated-file:dist/resource/js/diff.35abbf717e.js AI (source-diff): Minified rspack browser bundle; standard build output. ai
source-diff obfuscated-file:dist/resource/js/668.b7a2194a86.js AI (source-diff): Minified rspack browser bundle for React UI client; stable pattern across versions. ai
source-diff obfuscated-file:dist/resource/js/diff.e5a3ed7b78.js AI (source-diff): Minified rspack bundle; expected frontend asset. ai
source-diff net-exec-file:dist/resource/js/react.011ed2315a.js AI (source-diff): False positive on bundled React; no real dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/react.011ed2315a.js AI (source-diff): Minified React bundle; expected for this package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.6bbc42a150.js AI (source-diff): Minified rc-* component bundle; expected. ai
source-diff obfuscated-file:dist/resource/js/rc-0.9dcfc70e9d.js AI (source-diff): Minified rc-* component bundle; expected. ai
source-diff net-exec-file:dist/resource/js/index.92e372cea1.js AI (source-diff): False positive on bundled frontend code; no real dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/index.92e372cea1.js AI (source-diff): Minified rspack entry bundle; expected for this package. ai
source-diff net-exec-file:dist/resource/js/diff.e5a3ed7b78.js AI (source-diff): False positive on bundled frontend code; no real dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.9aa8cfe2d3.js AI (source-diff): Minified Ant Design icons chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.bba757a4e2.js AI (source-diff): Minified Ant Design chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.0f9f01b96d.js AI (source-diff): Minified Ant Design chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.a00e0dd3b8.js AI (source-diff): Minified Ant Design chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.4905c63481.js AI (source-diff): Minified Ant Design chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.19a675fc40.js AI (source-diff): Minified Ant Design chunk; standard for this package. ai
source-diff obfuscated-file:dist/resource/js/880.0a0fcc8aad.js AI (source-diff): Minified rspack bundle of app shell components; expected. ai
source-diff obfuscated-file:dist/resource/js/567.86a6194659.js AI (source-diff): Minified rspack bundle of Ant Design SVG icons; expected. ai
source-diff net-exec-file:dist/resource/js/49.131f657c61.js AI (source-diff): False positive on bundled Ant Design color utilities; no real net+exec. ai
source-diff obfuscated-file:dist/resource/js/49.131f657c61.js AI (source-diff): Minified rspack bundle of @ant-design/fast-color; expected frontend asset. ai
source-diff obfuscated-file:dist/resource/js/369.198e520a29.js AI (source-diff): Minified rspack bundle of slick-carousel UI code; standard for this client package. ai
source-diff obfuscated-file:dist/resource/js/142.350290ccb0.js AI (source-diff): Rspack-bundled React/AntD UI chunks; minification is expected for this client package. ai
source-diff net-exec-file:dist/resource/js/react.7c49fb5914.js AI (source-diff): False positive on bundled React runtime; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/react.7c49fb5914.js AI (source-diff): Bundled React runtime chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/rc-1.b43035e064.js AI (source-diff): Bundled rc-* component chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/rc-0.50becc7474.js AI (source-diff): Bundled rc-* component chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/index.7980e1096f.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/index.7980e1096f.js AI (source-diff): Bundled app entry chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/diff.73c9bbb75f.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/diff.73c9bbb75f.js AI (source-diff): Bundled diff-view chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.f0e8a5e979.js AI (source-diff): Bundled Ant Design icons chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.7ff8d78249.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.2fdffb4a35.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.10fadcad30.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.dcacdda382.js AI (source-diff): Bundled Ant Design Modal/Button chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.c6142e8905.js AI (source-diff): Bundled Ant Design component chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/713.4a558b34df.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/713.4a558b34df.js AI (source-diff): Bundled @ant-design/fast-color chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/494.345d38694e.js AI (source-diff): Bundled slick-carousel/slider chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/26.1c2637e740.js AI (source-diff): Bundled Ant Design icon SVG definitions; minified output expected. ai
source-diff net-exec-file:dist/resource/js/681.2b2ee6ceb1.js AI (source-diff): Network+exec pattern fires on bundled Ant Design color/theme code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/564.aba3fb731b.js AI (source-diff): Minified rspack chunk containing Rsdoctor app shell code; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/react.cad9d743fd.js AI (source-diff): Pattern fires on bundled React runtime; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/react.cad9d743fd.js AI (source-diff): Minified React runtime bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-1.b442c9d037.js AI (source-diff): Minified rc-* component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-0.1899feb0c1.js AI (source-diff): Minified rc-* component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.b3ef954307.js AI (source-diff): Minified Ant Design modal/button component bundle; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/index.b7a23597a1.js AI (source-diff): Pattern fires on bundled app entry code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/index.b7a23597a1.js AI (source-diff): Main rspack entry chunk; expected minified build artifact. ai
source-diff net-exec-file:dist/resource/js/diff.326a80ea66.js AI (source-diff): Pattern fires on bundled diff utility code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/diff.326a80ea66.js AI (source-diff): Minified diff-library chunk; expected build artifact for this build-analysis tool. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.56c57bb47f.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.1b59606406.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.90605e10b9.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/181.39d948030a.js AI (source-diff): Minified rspack chunk containing react-slick slider code; expected build artifact for this UI package. ai
source-diff obfuscated-file:dist/resource/js/681.2b2ee6ceb1.js AI (source-diff): Minified rspack chunk containing @ant-design/fast-color; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/881.9861e399a5.js AI (source-diff): Minified rspack chunk containing @ant-design/icons; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.423dc49a53.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/181.202c32f28e.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/630.d98cf14f77.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/681.2f02a25876.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/681.2f02a25876.js AI (source-diff): Minified React/ant-design UI bundle; network+exec pattern is from bundled fetch/eval in UI framework code. ai
source-diff obfuscated-file:dist/resource/js/70.b88e2c49cf.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.3da9e5560d.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.f4524a4f5e.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.864d7e37fa.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.a51fff4025.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.6d735fb087.js AI (source-diff): Minified ant-design-icons bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/diff.55f1533174.js AI (source-diff): Minified diff library bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/diff.55f1533174.js AI (source-diff): Minified diff library; network+exec pattern is false positive in bundled UI code. ai
source-diff obfuscated-file:dist/resource/js/index.f83e52ca10.js AI (source-diff): Main rspack entry bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/index.f83e52ca10.js AI (source-diff): Main rspack entry bundle; network+exec pattern is false positive in bundled UI code. ai
source-diff obfuscated-file:dist/resource/js/rc-0.6e1040359f.js AI (source-diff): Minified rc-* component bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.f953c6a3e4.js AI (source-diff): Minified rc-* component bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/react.a376b049da.js AI (source-diff): Minified React bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/react.a376b049da.js AI (source-diff): Minified React bundle; network+exec pattern is false positive in bundled UI code. ai
source-diff large-new-source-files AI (source-diff): UI client package ships bundled dist; large file count is expected for this package type. ai
source-diff net-exec-file:dist/resource/js/diff.c3f45786.js AI (source-diff): Diff library webpack chunk; no actual dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/diff.c3f45786.js AI (source-diff): Bundled diff library for UI; normal minified frontend output. ai
source-diff obfuscated-file:dist/resource/js/904.9d3c9413.js AI (source-diff): Bundled rsdoctor UI entry; normal minified frontend output. ai
source-diff obfuscated-file:dist/resource/js/vender.897ee4e5.js AI (source-diff): Vendor bundle; normal minified frontend output. ai
source-diff net-exec-file:dist/resource/js/index.d65452dc.js AI (source-diff): Main UI webpack bundle; no actual dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/index.d65452dc.js AI (source-diff): Main UI bundle; normal minified frontend output. ai
source-diff obfuscated-file:dist/resource/js/301.6fe78e8f.js AI (source-diff): Standard webpack-minified frontend bundle; content is legitimate ant-design color utilities. ai
source-diff obfuscated-file:dist/resource/js/vender.3b7dad84.js AI (source-diff): Minified vendor bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/vender.3b7dad84.js AI (source-diff): Webpack module loader pattern in vendor bundle; not malware. ai
source-diff obfuscated-file:dist/resource/js/rc-0.0ea117ca.js AI (source-diff): Minified rc-* component bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/index.7b4ed747.js AI (source-diff): Webpack module loader pattern; not malware. ai
source-diff obfuscated-file:dist/resource/js/index.7b4ed747.js AI (source-diff): Webpack-bundled app entry; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/301.6fe78e8f.js AI (source-diff): Webpack chunk with React/Ant Design code; net+exec pattern is webpack module loader, not malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.0c6e16e5.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.fbde6d43.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.6eaab0ba.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/301.29d82550.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color palette); not obfuscation. ai
source-diff net-exec-file:dist/resource/js/301.29d82550.js AI (source-diff): Webpack chunk with dynamic module loading; expected pattern for bundled SPA assets. ai
source-diff net-exec-file:dist/resource/js/vender.baa75fcf.js AI (source-diff): Webpack dynamic imports in vendor bundle; not malicious. ai
source-diff obfuscated-file:dist/resource/js/vender.baa75fcf.js AI (source-diff): Minified vendor bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/react.66832997.js AI (source-diff): Minified React bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/react.66832997.js AI (source-diff): React's dynamic module patterns; not malicious. ai
source-diff obfuscated-file:dist/resource/js/rc-1.9a056fca.js AI (source-diff): Minified rc-* UI component bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/rc-0.0816fdf8.js AI (source-diff): Minified rc-* UI component bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/index.803dd75a.js AI (source-diff): Webpack dynamic imports in SPA entry; not malicious. ai
source-diff obfuscated-file:dist/resource/js/index.803dd75a.js AI (source-diff): Main webpack entry bundle for SPA; expected minified output. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.fbcb77ae.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.005bd3a7.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/756.9e80a153.js AI (source-diff): Browser webpack chunk; network/eval patterns are normal React/antd bundle artifacts. ai
source-diff net-exec-file:dist/resource/js/vender.76f83665.js AI (source-diff): Vendor bundle; network/eval patterns are normal bundled library artifacts. ai
source-diff obfuscated-file:dist/resource/js/vender.76f83665.js AI (source-diff): Minified vendor bundle; legitimate bundled dependencies. ai
source-diff net-exec-file:dist/resource/js/react.e5b2c2b5.js AI (source-diff): React bundle; network/eval patterns are normal React runtime artifacts. ai
source-diff obfuscated-file:dist/resource/js/react.e5b2c2b5.js AI (source-diff): Minified React bundle; legitimate and expected. ai
source-diff obfuscated-file:dist/resource/js/rc-1.caad7806.js AI (source-diff): Minified rc-* component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/rc-0.ac891904.js AI (source-diff): Minified rc-* component bundle; legitimate UI library code. ai
source-diff net-exec-file:dist/resource/js/index.c3891998.js AI (source-diff): Browser bundle; network/eval patterns are normal React SPA artifacts. ai
source-diff obfuscated-file:dist/resource/js/index.c3891998.js AI (source-diff): Webpack-bundled app entry; minification is expected for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.a1b962c5.js AI (source-diff): Minified antd-icons bundle with SVG data; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.9f7db830.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.86e745f2.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.0ef4ec77.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.9709b0be.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.5f6e41bd.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/756.9e80a153.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color utilities); not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/339.425781b7.js AI (source-diff): Standard webpack-minified frontend bundle chunk; expected for a client UI package. ai
source-diff obfuscated-file:dist/resource/js/339.2a821d36.js AI (source-diff): Standard webpack-minified bundle chunk; expected for this frontend client package. ai
source-diff obfuscated-file:dist/resource/js/index.0d8b60cf.js AI (source-diff): Main webpack entry bundle for rsdoctor client UI; minification is expected. ai
source-diff net-exec-file:dist/resource/js/index.0d8b60cf.js AI (source-diff): Browser SPA bundle; network+exec pattern is false positive. ai
source-diff obfuscated-file:dist/resource/js/index.c069fd35.js AI (source-diff): Standard webpack entry bundle for rsdoctor client SPA. ai
source-diff net-exec-file:dist/resource/js/index.c069fd35.js AI (source-diff): Frontend SPA bundle; network+exec pattern is normal for browser JS apps. ai
source-diff obfuscated-file:dist/resource/js/rc-1.2d9b4e67.js AI (source-diff): Minified rc-* component library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.aabb43ad.js AI (source-diff): Minified rc-* component library chunk; expected for this UI package. ai
source-diff net-exec-file:dist/resource/js/index.9b701719.js AI (source-diff): Browser-side fetch+eval patterns in React SPA bundle; not a dropper. ai
source-diff obfuscated-file:dist/resource/js/index.9b701719.js AI (source-diff): Main app bundle; minified webpack output, not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.0f462273.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.c33e6cb4.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.3ce1955b.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.05f36d12.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.6bf63acc.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/715.a638a151.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/413.53dc0969.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/31.00f60aa6.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/339.17957712.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/vender.70d6647c.js AI (source-diff): Minified vendor bundle; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/187.54a8d2dc.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/index.a0a1553a.js AI (source-diff): Minified webpack entry bundle for rsdoctor client UI. ai
bogus-package bogus-package AI (bogus-package): Legitimate scoped package in a large monorepo; sparse README/keywords are expected. ai
source-diff net-exec-file:dist/resource/js/vender.70d6647c.js AI (source-diff): Vendor bundle (ant-design/rc components); eval patterns from minified third-party libs. ai
source-diff net-exec-file:dist/resource/js/index.a0a1553a.js AI (source-diff): Webpack bundle for a build-analysis UI; network+eval patterns are from bundler runtime. ai
source-diff net-exec-file:dist/resource/js/react.17aa4f75.js AI (source-diff): React runtime legitimately uses eval/new Function and XHR; not malware. ai
source-diff obfuscated-file:dist/resource/js/react.17aa4f75.js AI (source-diff): Minified React bundle; long lines are standard minification, not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/133.265150e3.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color utilities); not obfuscation. ai
source-diff net-exec-file:dist/resource/js/133.265150e3.js AI (source-diff): Webpack chunk with dynamic module loading; no malicious network calls evident in samples. ai
source-diff obfuscated-file:dist/resource/js/index.0768c070.js AI (source-diff): Webpack-bundled main entry; standard minification for a frontend client package. ai
source-diff net-exec-file:dist/resource/js/index.0768c070.js AI (source-diff): Webpack dynamic imports in browser bundle; not malicious dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/187.892c5bc9.js AI (source-diff): Standard webpack-minified chunk of a React/ECharts SPA; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.fd736134.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.2e00f600.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.cf9e3262.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.59c4f277.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/413.463df149.js AI (source-diff): Standard webpack-minified chunk; ECharts view chart code. ai
source-diff obfuscated-file:dist/resource/js/index.b1d41f5e.js AI (source-diff): Main SPA entry bundle; minified React app, not obfuscated malware. ai
source-diff net-exec-file:dist/resource/js/index.b1d41f5e.js AI (source-diff): React SPA fetches build stats data; dynamic require is standard webpack runtime, not dropper. ai
source-diff obfuscated-file:dist/resource/js/rc-0.201d292e.js AI (source-diff): Standard webpack-minified rc-* component chunk. ai
source-diff obfuscated-file:dist/resource/js/rc-1.ad04108d.js AI (source-diff): Standard webpack-minified rc-* component chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.1ca4a07e.js AI (source-diff): Standard webpack-minified Ant Design Icons chunk. ai
source-diff obfuscated-file:dist/resource/js/715.beadd8b5.js AI (source-diff): Standard webpack-minified chunk; echarts-for-react component. ai
source-diff obfuscated-file:dist/resource/js/339.d97a5eb5.js AI (source-diff): Standard webpack-minified chunk; contains rsdoctor route/constant definitions. ai
source-diff obfuscated-file:dist/resource/js/31.e37348c3.js AI (source-diff): Standard webpack-minified chunk; ECharts rendering code. ai
source-diff obfuscated-file:dist/resource/js/rc-0.f5bcb33d.js AI (source-diff): Standard webpack-minified rc-component bundle. ai
source-diff net-exec-file:dist/resource/js/react.f1c1c97a.js AI (source-diff): Network+exec pattern in webpack React bundle is false positive for this client-side web app package. ai
source-diff net-exec-file:dist/resource/js/index.5cff221c.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive for this client-side web app package. ai
source-diff net-exec-file:dist/resource/js/diff.6498e93a.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive for this client-side web app package. ai
source-diff net-exec-file:dist/resource/js/383.2e75ce49.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive; no actual fetch+eval pattern visible in sample. ai
source-diff obfuscated-file:dist/resource/js/react.f1c1c97a.js AI (source-diff): Standard webpack-minified React bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-1.08d0910e.js AI (source-diff): Standard webpack-minified rc-component bundle. ai
source-diff obfuscated-file:dist/resource/js/index.5cff221c.js AI (source-diff): Standard webpack-minified main entry bundle for rsdoctor client UI. ai
source-diff obfuscated-file:dist/resource/js/diff.6498e93a.js AI (source-diff): Standard webpack-minified diff library bundle for rsdoctor client UI. ai
source-diff obfuscated-file:dist/resource/js/641.c0cd2597.js AI (source-diff): Standard webpack-minified UI bundle (slick carousel chunk). ai
source-diff obfuscated-file:dist/resource/js/601.dc26c158.js AI (source-diff): Standard webpack-minified UI bundle for rsdoctor client. ai
source-diff obfuscated-file:dist/resource/js/577.10ff2379.js AI (source-diff): Standard webpack-minified UI bundle (ant-design icons chunk). ai
source-diff obfuscated-file:dist/resource/js/383.2e75ce49.js AI (source-diff): Standard webpack-minified UI bundle for rsdoctor client; minification is expected for this package. ai
source-diff net-exec-file:dist/resource/js/index.e62055d7.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/vender.9840e009.js AI (source-diff): Minified vendor bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/react.419e5c4a.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/react.419e5c4a.js AI (source-diff): Minified React bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-0.327357c3.js AI (source-diff): Minified rc-* bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-1.eb2754d2.js AI (source-diff): Minified rc-* bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/702.19a48c2a.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact for this frontend client package. ai
source-diff obfuscated-file:dist/resource/js/709.d24e2ffb.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/709.d24e2ffb.js AI (source-diff): Webpack bundle with fetch/dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/736.04fd2dc8.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/904.ecbb2c06.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.71243426.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.6050f2c5.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.16432452.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.23ce91b6.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.97833ea2.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.6f529e48.js AI (source-diff): Minified ant-design-icons bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/diff.e7ce9b7c.js AI (source-diff): Minified diff library bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/diff.e7ce9b7c.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/index.e62055d7.js AI (source-diff): Minified main bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.e823b890.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.32845f6f.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.c067cf25.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/304.aa917bbe.js AI (source-diff): Standard webpack-minified ant-design/react bundle; not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA provenance is expected for this monorepo. ai
publish-pattern dormant-publish AI (publish-pattern): Version gap matches legitimate v1.1.x→v1.2.x release cycle for rsdoctor monorepo. ai
source-diff net-exec-file:dist/resource/js/vender.0a509a76.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/react.3416b75d.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/index.dd8eb261.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/304.aa917bbe.js AI (source-diff): Browser webpack chunk; fetch+dynamic patterns are normal in bundled browser UI code. ai
source-diff obfuscated-file:dist/resource/js/vender.0a509a76.js AI (source-diff): Standard webpack-minified vendor bundle. ai
source-diff obfuscated-file:dist/resource/js/react.3416b75d.js AI (source-diff): Standard webpack-minified React bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-1.a0853e1e.js AI (source-diff): Standard webpack-minified rc-* bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-0.93ad3cb8.js AI (source-diff): Standard webpack-minified rc-* bundle. ai
source-diff obfuscated-file:dist/resource/js/index.dd8eb261.js AI (source-diff): Standard webpack-minified main entry bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.f6718859.js AI (source-diff): Standard webpack-minified ant-design-icons bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.fc287b65.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.748849f0.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.1134e91c.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/6.443c6bd9.js AI (source-diff): webpack chunk loading pattern in browser SPA bundle; not dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.f0a5055d.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.990bb762.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/6.443c6bd9.js AI (source-diff): Standard webpack-minified browser bundle; content is recognizable Ant Design color utilities. ai
source-diff net-exec-file:dist/resource/js/react.9f38b670.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/vender.77ed69e7.js AI (source-diff): Minified vendor bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/vender.77ed69e7.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.afd634fc.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/react.9f38b670.js AI (source-diff): Minified React bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-2.a9ba63e5.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.be16b817.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.7f6c32e1.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/index.3448b987.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.8a716a60.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/index.3448b987.js AI (source-diff): Minified webpack entry bundle for SPA; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.ae049bf7.js AI (source-diff): Minified Ant Design icons bundle; SVG icon data clearly visible in sample. ai

Versions (showing 55 of 55)

Version Deps Published
1.6.1 0 / 19
1.6.0 0 / 19
1.5.18 0 / 19
1.5.17 0 / 19
1.5.16 0 / 19
1.5.15 0 / 19
1.5.14 0 / 19
1.5.13 0 / 19
1.5.12 0 / 19
1.5.11 0 / 19
1.5.10 0 / 19
1.5.9 0 / 19
1.5.8 0 / 19
1.5.7 0 / 19
1.5.6 0 / 19
1.5.5 0 / 19
1.5.4 0 / 19
1.5.3 0 / 19
1.5.2 0 / 19
1.5.1 0 / 19
1.5.0 0 / 19
1.4.0 0 / 19
1.3.16 0 / 19
1.3.15 0 / 19
1.3.14 0 / 19
1.3.13 0 / 19
1.3.12 0 / 19
1.3.11 0 / 19
1.3.10 0 / 19
1.3.9 0 / 19
1.3.8 0 / 19
1.3.7 0 / 19
1.3.3 0 / 19
1.3.2 0 / 19
1.3.1 0 / 19
1.3.0 0 / 19
1.2.3 0 / 19
1.2.2 0 / 19
1.2.1 0 / 19
1.2.0 0 / 19
1.1.11 0 / 19
1.1.10 0 / 19
1.1.9 0 / 19
1.1.8 0 / 19
1.1.7 0 / 19
1.1.6 0 / 19
1.1.5 0 / 19
1.1.4 0 / 19
1.1.3 0 / 19
1.1.2 0 / 19
1.1.1 0 / 19
1.1.0 0 / 19
1.0.2 0 / 19
1.0.1 0 / 18
1.0.0 0 / 18

v1.6.1

6 findings
HIGH New obfuscated file: dist/resource/js/226.b4954a9cff.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.e2c900a07a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.e2c900a07a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.7997b81b6e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.7997b81b6e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

16 findings
HIGH New obfuscated file: dist/resource/js/140.b467c9d598.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/272.462a16751f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/412.3f86aaed12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/864.3ff7582d41.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/864.3ff7582d41.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.950b3b9170.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.6508eaabf7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.5234e97504.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.a193b5d883.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.a193b5d883.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.dc3a8e9e06.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.dc3a8e9e06.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc.28ae4416c7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.be46a29bc2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.be46a29bc2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.18

20 findings
HIGH New obfuscated file: dist/resource/js/154.ff7cbe5fa3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/154.ff7cbe5fa3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/377.133c6e0d1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/490.14be1ab9e7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/741.6e6ef987ba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.96adf8f069.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.68946cc6ce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.4c63ffcea7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.e483f7bab7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.76b9e0718f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6a7e8378bb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.2c6bb8f087.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.2c6bb8f087.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.a5e4c60a9b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.a5e4c60a9b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.9011058b86.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.317f7815ba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.06a00a7236.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.06a00a7236.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.17

6 findings
HIGH New obfuscated file: dist/resource/js/668.5625ee4138.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.b164bb1239.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.b164bb1239.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.d69991f975.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.d69991f975.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.4

8 findings
HIGH New obfuscated file: dist/resource/js/116.e9b0bfeb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/116.e9b0bfeb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/904.e574a404.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.e4f3458a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.e4f3458a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.f504900b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.f504900b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.3

12 findings
HIGH New obfuscated file: dist/resource/js/375.29108e01.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/375.29108e01.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/510.e39f3818.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/538.26a222ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/611.00341793.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.d7e8e4b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.d7e8e4b5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.2c346ce0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.2c346ce0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.5662d149.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.08a5ec82.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.2

14 findings
HIGH New obfuscated file: dist/resource/js/159.bca660e6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/246.d2c7c8d3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/384.d4e59acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/384.d4e59acc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/610.d58c44f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.f47d35f1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.f47d35f1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.fdf47698.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.fdf47698.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.bd9999ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.3dfe4388.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.3dfe4388.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.964dfc5c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

14 findings
HIGH New obfuscated file: dist/resource/js/159.3897a28e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/246.d2c7c8d3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/384.d4e59acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/384.d4e59acc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/610.d58c44f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.48b74bd1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.48b74bd1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.d0420c7a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.d0420c7a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.bd9999ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.3dfe4388.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.3dfe4388.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.964dfc5c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

14 findings
HIGH New obfuscated file: dist/resource/js/197.aa320ba5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/197.aa320ba5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/610.d58c44f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/791.5f557611.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/883.0a0d6fad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.960a19ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.960a19ea.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.3304dad7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.3304dad7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.1aa34d68.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.72d3d85b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.72d3d85b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.4a6fee86.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

19 findings
HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/640.874771ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/732.68bd2b07.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/732.68bd2b07.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/868.3acb2b29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-2.b6faaf27.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.08818b1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a0dc17ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.58e58f64.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.58e58f64.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.826fcab4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.826fcab4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.158198ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.16

19 findings
HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/640.874771ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/732.68bd2b07.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/732.68bd2b07.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/868.1ab3f84e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-2.b6faaf27.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.08818b1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a0dc17ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.3a9247c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.3a9247c5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.77726613.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.77726613.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.158198ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.15

19 findings
HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/640.874771ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/732.68bd2b07.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/732.68bd2b07.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/868.eb7974ae.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-2.b6faaf27.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.08818b1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a0dc17ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.0561562f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.0561562f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.38891aa2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.38891aa2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.158198ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.14

19 findings
HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/640.874771ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/732.68bd2b07.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/732.68bd2b07.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/868.ba723e78.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-2.b6faaf27.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.08818b1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a0dc17ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.0561562f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.0561562f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.38891aa2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.38891aa2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.158198ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.13

19 findings
HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/640.874771ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/732.68bd2b07.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/732.68bd2b07.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/868.21f578e4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-2.b6faaf27.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.08818b1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a0dc17ef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.dc787e83.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.dc787e83.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.12ab02e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.12ab02e5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.158198ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.12

18 findings
HIGH New obfuscated file: dist/resource/js/205.9c1c308a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/205.9c1c308a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/349.1caba575.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.ad96e5a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.624aa7d5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.81f1287f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.81f1287f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.28a83613.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.28a83613.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.ced7dd51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.ced7dd51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.8fa54b46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.11

18 findings
HIGH New obfuscated file: dist/resource/js/118.35589783.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/205.9c1c308a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/205.9c1c308a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.ad96e5a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.aa649b3f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.367ab40b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.367ab40b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.1d92bbb5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.1d92bbb5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.5d8fd297.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.5d8fd297.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.8fa54b46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.10

18 findings
HIGH New obfuscated file: dist/resource/js/118.35589783.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/205.9c1c308a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/205.9c1c308a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.ad96e5a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.aa649b3f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.367ab40b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.367ab40b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.1d92bbb5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.1d92bbb5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.5d8fd297.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.5d8fd297.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.8fa54b46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.9

18 findings
HIGH New obfuscated file: dist/resource/js/118.35589783.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/205.9c1c308a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/205.9c1c308a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.ad96e5a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.aa649b3f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.972c8afa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.972c8afa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.1c12c054.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.1c12c054.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.5d8fd297.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.5d8fd297.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.8fa54b46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.8

18 findings
HIGH New obfuscated file: dist/resource/js/118.35589783.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/483.925ce01f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/483.925ce01f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.333bc670.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.aa649b3f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.49da51ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.49da51ac.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.abb379a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.abb379a1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.5d8fd297.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.5d8fd297.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.8fa54b46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.7

18 findings
HIGH New obfuscated file: dist/resource/js/118.35589783.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/410.a54d7b65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/410.a54d7b65.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/512.c80dd09b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/682.652df2a0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-1.0aa20e29.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-4.51693c58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.aa649b3f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/diff.5a62bbb0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.5a62bbb0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.e56057d5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.e56057d5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.a0e85196.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/rc-1.06a42c11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.93256790.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.93256790.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.e233236e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

9 findings
HIGH New obfuscated file: dist/resource/js/751.3fa00fdf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/751.3fa00fdf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/index.17450227.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/index.17450227.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.f85b41a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.f85b41a1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.7010d5f5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/vender.7010d5f5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

9 findings
HIGH New obfuscated file: dist/resource/js/751.6608c443.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/751.6608c443.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/index.66a99a77.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/index.66a99a77.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/react.e3c21fa0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/react.e3c21fa0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/resource/js/vender.7010d5f5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/resource/js/vender.7010d5f5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.