← Home

@scalar/api-reference

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cameronrohanimarclavescalar_geoffhwkrhanspagelamritkbgrcsscalar-machine

Keywords

componentdocumentationopenapireferencespecswaggervuevue3

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-YU9KKgvZ.js AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/modal-WJ4Gcv8N.js AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-B-Nhpn0q.js AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. ai
source-diff net-exec-file:dist/browser/chunks/vendor-BqFs9NIb.js AI (source-diff): Bundled vendor chunk; net+exec patterns are library code, no hostile target. ai
source-diff net-exec-file:dist/browser/chunks/vendor-7kt1IXrE.js AI (source-diff): Vendor bundle for a browser API-reference component; net/exec are library primitives, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BkjPSVNK.js AI (source-diff): Vite/Rollup minified browser bundle with Scalar banner; not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/modal-CI1RYR0j.js AI (source-diff): Minified bundled browser chunk; benign build output. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CnSl7YW1.js AI (source-diff): Minified bundled Vue component chunk; benign build output. ai
source-diff obfuscated-file:dist/browser/chunks/modal-BLBi4S4R.js AI (source-diff): Vite-bundled dist chunk; minified build output. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D7J_MHKY.js AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. ai
source-diff net-exec-file:dist/browser/chunks/vendor-DHN5fsxL.js AI (source-diff): Bundled vendor chunk; net+exec is browser-runtime library code, no hostile destination. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Fb0snAee.js AI (source-diff): Vite-bundled dist chunk; minified build output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-BPQqqkn-.js AI (source-diff): Bundled vendor chunk; net+exec are library primitives, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CysYmeeN.js AI (source-diff): Vite-bundled dist chunk; minified build output. ai
source-diff obfuscated-file:dist/browser/chunks/modal-wI0tG53V.js AI (source-diff): Vite-bundled dist chunk; minified build output. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-C3QiXv0S.js AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. ai
source-diff obfuscated-file:dist/browser/chunks/modal-B4LeCbAi.js AI (source-diff): Minified Vite bundle; normal ESM imports, not obfuscated. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D4DCmV5y.js AI (source-diff): Minified Vite bundle with Scalar banner; long lines are build output, not obfuscation. ai
source-diff net-exec-file:dist/browser/chunks/vendor-BNhbieDE.js AI (source-diff): Vendor browser bundle; net+exec patterns inherent to bundled deps, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C5aaO8tA.js AI (source-diff): Minified Vue component bundle; build output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-Dp5Q6nDX.js AI (source-diff): Bundled vendor chunk of a browser API-reference UI; network+eval is normal Vue runtime, no hostile destination. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CPqxdcxM.js AI (source-diff): Minified vite bundle output, not obfuscation; per-file path won't recur but pattern is benign build artifact. ai
source-diff obfuscated-file:dist/src-DJwsRvMU.js AI (source-diff): Bundled Vite build output, readable ESM imports; not true obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DfHAfVG5.js AI (source-diff): Bundled minified Vue component chunk. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-uEJhFXkB.js AI (source-diff): Bundled minified dist chunk, build output. ai
source-diff obfuscated-file:dist/browser/chunks/modal-VSnkfbyL.js AI (source-diff): Bundled minified dist chunk with Scalar banner, not obfuscation. ai
source-diff net-exec-file:dist/browser/chunks/vendor-C5HmjoOQ.js AI (source-diff): Minified Vite vendor bundle; long lines are build output, no malicious behavior. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BhUn0w1j.js AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/browser/chunks/vendor-BeJNu9KM.js AI (source-diff): Bundled vendor chunk; net+exec patterns are inherent to browser bundle, no hostile destination. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-BUzf4Z_k.js AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/modal-CZI71Aau.js AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/modal-B2flFlrc.js AI (source-diff): Bundled dist chunk; minified build output. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DX-rWLia.js AI (source-diff): Vite-bundled dist chunk, long lines are minification not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DuE2oAzR.js AI (source-diff): Bundled dist chunk; minified build output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-DPVN2O_H.js AI (source-diff): Bundled vendor chunk; net+exec patterns are Vue runtime build output, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cg0WEkPQ.js AI (source-diff): Minified Vite bundle chunk; build output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-DfF1NNVy.js AI (source-diff): Bundled Vue vendor chunk; net+exec is standard browser runtime, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Bd03__M5.js AI (source-diff): Minified Vite bundle chunk with Scalar banner; not obfuscation. ai
source-diff obfuscated-file:dist/browser/chunks/modal-DXAlZ4Y8.js AI (source-diff): Minified Vite bundle chunk; build output. ai
source-diff obfuscated-file:dist/src-DqcYVBWI.js AI (source-diff): Vite/rollup bundle output with readable ESM imports, not obfuscation; stable for this build tool. ai
source-diff obfuscated-file:dist/components/GettingStarted.vue.script.js AI (source-diff): Vite/Vue bundled component output, not obfuscation; readable imports and first-party fetch target. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-c6CQmaLr.js AI (source-diff): Vite-bundled minified chunk with Scalar banner, not obfuscation. ai
dependencies unvetted-dep:@scalar/client-app AI (dependencies): First-party sibling package in the same monorepo. ai
phantom-deps phantom-dep:unhead AI (phantom-deps): Used in config, not a real risk. ai
phantom-deps phantom-dep:unified AI (phantom-deps): Used via config files, not direct import; benign. ai
phantom-deps phantom-dep:postcss-nested AI (phantom-deps): Used via PostCSS config, not direct import; stable false positive. ai
dependencies unvetted-dep:@scalar/api-client-modal AI (dependencies): First-party @scalar sibling package within same monorepo. ai
source-diff obfuscated-file:dist/browser/chunks/modal-BvqLUPs5.js AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. ai
source-diff net-exec-file:dist/browser/chunks/vendor-BlFFskFr.js AI (source-diff): Bundled vendor chunk; net+exec are inherent to browser bundle, no hostile target. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CNs5mxby.js AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-D_L-rtQC.js AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. ai
source-diff obfuscated-file:dist/browser/chunks/modal-DQLVQL1H.js AI (source-diff): Minified bundle chunk, official banner; build output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-CMNc6l_z.js AI (source-diff): Standard vendor bundle for browser build; dual-use in minified output, no hostile destination. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cb7P6-e4.js AI (source-diff): Minified Vue component bundle chunk; build output. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DeQ6jlD2.js AI (source-diff): Vite/Rollup minified bundle chunk with official Scalar banner; build output not obfuscation. ai
source-diff net-exec-file:dist/browser/chunks/vendor-wW8jg8wN.js AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies (Vue, etc.). ai
source-diff obfuscated-file:dist/browser/chunks/modal-BZzcBkVp.js AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CesFQ_Ax.js AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C14zmVNI.js AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. ai
phantom-deps phantom-dep:flatted AI (phantom-deps): Declared dep used transitively or in config; stable pattern for this package. ai
provenance publisher-changed AI (provenance): scalar_geoff is an established Scalar org publisher with 446 approved packages. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Dv0uBVU9.js AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. ai
source-diff net-exec-file:dist/browser/chunks/vendor-Cx_C-51y.js AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-ZmlutrTU.js AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. ai
source-diff obfuscated-file:dist/browser/chunks/modal-DHI6k89v.js AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. ai
source-diff encoded-string-file:dist/browser/standalone.js AI (source-diff): Bundled standalone build with CodeMirror bidi char-class tables; stable minified output pattern. ai
source-diff net-exec-file:dist/browser/chunks/vendor-nugWm4eq.js AI (source-diff): Bundled vendor chunk for browser dist; network+exec pattern is normal for UI framework bundles. ai
source-diff obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-XkIzhvc0.js AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. ai
source-diff obfuscated-file:dist/browser/chunks/modal-Bp9V4D2s.js AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BXB1nZKJ.js AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. ai
phantom-deps phantom-dep:@scalar/openapi-upgrader AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. ai
phantom-deps phantom-dep:@scalar/object-utils AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. ai
phantom-deps phantom-dep:@scalar/json-magic AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. ai
phantom-deps phantom-dep:@floating-ui/vue AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. ai
phantom-deps phantom-dep:type-fest AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. ai
phantom-deps phantom-dep:js-base64 AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. ai
source-diff obfuscated-file:dist/browser/chunks/browser-67K6wmG9.js AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. ai
source-diff large-new-source-files AI (source-diff): New standalone ESM build target adds expected browser bundle chunks. ai
source-diff obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DIIVMX31.js AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. ai
dependencies unvetted-dep:@scalar/themes AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/workspace-store AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/use-toasts AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/components AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/api-client AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/agent-chat AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/use-hooks AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/oas-utils AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/sidebar AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai
dependencies unvetted-dep:@scalar/icons AI (dependencies): Same scalar monorepo; legitimate sibling dep. ai

Versions (showing 51 of 395)

View all versions
Version Deps Published
1.63.0 25 / 18
1.62.9 25 / 18
1.62.8 25 / 18
1.62.7 25 / 18
1.62.6 25 / 18
1.62.5 25 / 18
1.62.4 25 / 18
1.62.3 25 / 18
1.62.2 25 / 18
1.62.1 25 / 18
1.62.0 25 / 18
1.61.0 24 / 18
1.60.0 24 / 18
1.59.3 24 / 18
1.59.2 24 / 18
1.59.1 24 / 18
1.59.0 24 / 18
1.58.0 24 / 18
1.57.5 24 / 18
1.57.4 24 / 18
1.57.3 24 / 18
1.57.2 24 / 18
1.57.1 24 / 18
1.57.0 24 / 18
1.55.3 22 / 18
1.55.2 22 / 18
1.55.1 22 / 17
1.55.0 23 / 17
1.54.0 23 / 17
1.53.1 23 / 17
1.53.0 23 / 17
1.52.6 23 / 17
1.52.5 23 / 17
1.52.4 23 / 17
1.52.3 23 / 17
1.52.2 23 / 16
1.52.1 23 / 16
1.52.0 23 / 16
1.51.0 23 / 16
1.50.0 23 / 16
1.49.8 24 / 16
1.49.7 24 / 18
1.49.6 24 / 18
1.49.5 24 / 18
1.49.4 24 / 18
1.49.3 24 / 18
1.49.2 24 / 18
1.49.1 24 / 18
1.49.0 24 / 19
1.48.8 24 / 19
1.48.7 24 / 19

v1.63.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.9

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-YU9KKgvZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-WJ4Gcv8N.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-B-Nhpn0q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-BqFs9NIb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.8

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-BkjPSVNK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-CI1RYR0j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-CnSl7YW1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-7kt1IXrE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.7

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-DX-rWLia.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-B2flFlrc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-DuE2oAzR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-DPVN2O_H.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.6

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-Bd03__M5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-DXAlZ4Y8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-Cg0WEkPQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-DfF1NNVy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.5

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-DeQ6jlD2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-DQLVQL1H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-Cb7P6-e4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-CMNc6l_z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.4

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-uEJhFXkB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-VSnkfbyL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-DfHAfVG5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-C5HmjoOQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.3

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-CNs5mxby.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-BvqLUPs5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-D_L-rtQC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-BlFFskFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.2

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-c6CQmaLr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-BvqLUPs5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-D_L-rtQC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-BlFFskFr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.1

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-D7J_MHKY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-BLBi4S4R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-Fb0snAee.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-DHN5fsxL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.62.0

5 findings
HIGH New obfuscated file: dist/browser/chunks/AgentScalarChatInterface-C3QiXv0S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/modal-wI0tG53V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/browser/chunks/ScalarTextInput.vue-CysYmeeN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/chunks/vendor-BPQqqkn-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.6

2 findings
HIGH New obfuscated file: dist/components/GettingStarted.vue.script.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.5

2 findings
HIGH New obfuscated file: dist/components/GettingStarted.vue.script.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.4

2 findings
HIGH New obfuscated file: dist/components/GettingStarted.vue.script.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.3

2 findings
HIGH New obfuscated file: dist/src-DJwsRvMU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.2

2 findings
HIGH New obfuscated file: dist/src-DJwsRvMU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.49.1

2 findings
HIGH New obfuscated file: dist/src-DqcYVBWI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.