← Home

@sentio/runtime

29
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

longwallendragonphilz3906pooytr1rnonslzx_lizixingfrozenluo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:lib/chunk-Z6R7IWRT.js AI (source-diff): Bundled vendor deps, same tsup build output pattern. ai
source-diff net-exec-file:lib/chunk-X5CIKWKP.js AI (source-diff): Bundled vendored deps inside tsup chunk; same false-positive pattern as sibling chunk. ai
source-diff net-exec-file:lib/chunk-CFG44J2I.js AI (source-diff): Bundled vendored deps (protobufjs/graceful-fs) inside tsup chunk, not injected exfil/loader code. ai
semgrep semgrep:eval-usage AI (semgrep): Bundled vendor code (fs-extra/grpc chunks), not package-authored eval. ai
semgrep semgrep:base64-decode AI (semgrep): False positive on minified string literals in bundled deps. ai
semgrep semgrep:shady-links-tlds AI (semgrep): Matches on bundled template-literal artifacts, not real URLs. ai
bogus-package bogus-package AI (bogus-package): Established, widely-used runtime; metadata gaps are cosmetic, not spam. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Bundled code pattern, no malicious behavior evidenced. ai
source-diff net-exec-file:lib/chunk-ASPTWJQG.js AI (source-diff): tsup-bundled deps (grpc/protobufjs/otel/fs-extra); not obfuscation, no exfil destination ai
source-diff net-exec-file:lib/chunk-M7AXVHAR.js AI (source-diff): tsup-bundled protobufjs/deps; base64 encode is protobuf, no hostile target ai
source-diff net-exec-file:lib/chunk-VRBW2KLF.js AI (source-diff): Bundled build chunk (tsup output), not obfuscated malware; sample shows standard module polyfills. ai
source-diff net-exec-file:lib/chunk-WQZPRG3V.js AI (source-diff): Bundled build chunk (tsup output), not obfuscated malware; sample shows standard fs/graceful-fs shims. ai
source-diff obfuscated-file:dist/service-v3-CUCRzxpl.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/plugin-BKPj92hO.js AI (source-diff): Bundled build output. ai
source-diff net-exec-file:lib/chunk-U6BJVJ62.js AI (source-diff): Bundled base64/protobuf helper code, not malicious loader. ai
source-diff net-exec-file:lib/chunk-EQHBEFKX.js AI (source-diff): Bundled third-party libs (graceful-fs etc.) via tsup, not a dropper. ai
source-diff obfuscated-file:dist/service-v3-C-P_jSmD.js AI (source-diff): Bundled build output, not true obfuscation. ai
source-diff obfuscated-file:dist/service-v3-3iFcydRx.js AI (source-diff): Bundled output chunk. ai
source-diff obfuscated-file:dist/plugin-BZBEYadJ.js AI (source-diff): Bundled tsdown output, not true obfuscation. ai
source-diff obfuscated-file:src/gen/service/common/protos/common_pb.ts AI (source-diff): Generated protobuf descriptor file with base64 payload, not obfuscation. ai
source-diff net-exec-file:dist/processor-runner.js AI (source-diff): child_process.fork of same file for worker processes, documented runtime behavior. ai
source-diff obfuscated-file:src/gen/processor/protos/processor_pb.ts AI (source-diff): Generated protobuf descriptor file, same as above. ai
source-diff obfuscated-file:dist/esm-Ajeyb2yg.js AI (source-diff): Bundled minified output from new tsdown build, not obfuscation. ai
source-diff obfuscated-file:dist/plugin-zKrh74uo.js AI (source-diff): Bundled minified output from new tsdown build, not obfuscation. ai
source-diff obfuscated-file:dist/processor-runner.js AI (source-diff): Bundled minified CLI entrypoint, matches documented bin target. ai
source-diff obfuscated-file:dist/service-v3-BXdclcET.js AI (source-diff): Bundled minified output from new tsdown build. ai
source-diff net-exec-file:lib/chunk-LK4RU6UR.js AI (source-diff): Bundled tsup output; samples show graceful-fs and fs-extra wrappers, not dropper/loader malware. ai
source-diff net-exec-file:lib/chunk-3DTPHRJ2.js AI (source-diff): Bundled tsup output; samples show standard library code (protobuf, base64, event emitter), not malware. ai
source-diff net-exec-file:lib/chunk-TBN64DSW.js AI (source-diff): Bundled library code (protobuf/base64/event-emitter); no actual dropper payload present in samples. ai
source-diff net-exec-file:lib/chunk-WUUWUOFG.js AI (source-diff): Bundled library code (graceful-fs, fs-extra wrappers); no actual dropper payload present in samples. ai
provenance publisher-changed AI (provenance): Legitimate migration to GitHub Actions CI/CD publishing; SLSA provenance attestation confirms integrity. ai
publish-pattern rapid-publish AI (publish-pattern): CI/CD pipeline publishing multiple packages in sequence; consistent with automated release workflow. ai
semgrep semgrep:env-spread AI (semgrep): process.env spread into child fork options is standard Node.js subprocess pattern for this processor runner. ai
phantom-deps phantom-dep:piscina AI (phantom-deps): piscina is declared as a runtime dependency in package.json; phantom-dep heuristic is a false positive here. ai

Versions (showing 29 of 29)

Version Deps Published
4.3.4 1 / 3
4.3.3 1 / 3
4.3.2 1 / 3
4.3.1 1 / 3
4.3.0 1 / 3
4.2.2 1 / 3
4.2.1 1 / 3
4.2.0 1 / 3
4.1.0 1 / 3
4.0.0 1 / 2
3.8.1 1 / 2
3.8.0 1 / 2
3.7.0 1 / 2
3.6.2 1 / 2
3.6.1 1 / 2
3.6.0 1 / 2
3.5.0 1 / 2
3.4.2 1 / 2
3.4.1 1 / 2
3.4.0 1 / 2
3.3.0 1 / 2
3.2.0 1 / 2
3.1.0 1 / 2
3.0.1 1 / 2
3.0.0 1 / 2
2.63.1 1 / 2
2.63.0 1 / 2
2.62.7 1 / 2
2.62.6 1 / 2

v4.3.4

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-zKrh74uo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-BXdclcET.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.3

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-zKrh74uo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-C-P_jSmD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.2

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.2

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.1

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.0

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BZBEYadJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-3iFcydRx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.0

8 findings
HIGH New obfuscated file: dist/esm-Ajeyb2yg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/plugin-BKPj92hO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/processor-runner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/processor-runner.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/service-v3-CUCRzxpl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/service/common/protos/common_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/gen/processor/protos/processor_pb.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.2

4 findings
HIGH New file with network + code execution: lib/chunk-ASPTWJQG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-M7AXVHAR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zfy0701 → philz3906 (on 2026-03-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.1

4 findings
HIGH New file with network + code execution: lib/chunk-ASPTWJQG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-M7AXVHAR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zfy0701 → philz3906 (on 2026-03-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.0

3 findings
HIGH New file with network + code execution: lib/chunk-CFG44J2I.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-X5CIKWKP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

3 findings
HIGH New file with network + code execution: lib/chunk-CFG44J2I.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-X5CIKWKP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

3 findings
HIGH New file with network + code execution: lib/chunk-VRBW2KLF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-WQZPRG3V.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

3 findings
HIGH New file with network + code execution: lib/chunk-VRBW2KLF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: lib/chunk-Z6R7IWRT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.62.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.62.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.