← Home

@signalk/server-admin-ui

Signal K server admin webapp

25
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tkurkisbenderpanaaj

Keywords

signalk-webapp

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:public/assets/bootstrap-CkVvyXgI.js AI (source-diff): Bundled frontend JS; network/eval patterns are from bundler runtime, not a dropper. ai
source-diff obfuscated-file:public/assets/bootstrap-CkVvyXgI.js AI (source-diff): Minified Vite build output, not true obfuscation; contains readable React library code. ai
source-diff obfuscated-file:public/assets/bootstrap-Dl8NOv2y.js AI (source-diff): Vite bundle output, bundler banner present, standard React/vendor code. ai
source-diff net-exec-file:public/assets/bootstrap-Dl8NOv2y.js AI (source-diff): Vite-bundled app entry, no malicious network/exec behavior found. ai
source-diff obfuscated-file:public/assets/bootstrap-6CM60CZx.js AI (source-diff): Vite bundle output for React app, not obfuscation. ai
source-diff net-exec-file:public/assets/bootstrap-6CM60CZx.js AI (source-diff): Vite bundle output, module federation loading is expected. ai
source-diff net-exec-file:public/assets/bootstrap-bNZv2cMS.js AI (source-diff): Bundled federation runtime code, no malicious network/exec behavior evident. ai
source-diff net-exec-file:public/assets/index.cjs-qNTcCtpj.js AI (source-diff): Federation manifest loader code, no malicious destination found. ai
source-diff obfuscated-file:public/assets/index.cjs-qNTcCtpj.js AI (source-diff): Module-federation runtime bundle, not obfuscation. ai
source-diff obfuscated-file:public/assets/index-C0euSWDO.js AI (source-diff): Minified React/scheduler library code, standard bundler output. ai
source-diff obfuscated-file:public/assets/index-BEQk0SN_.js AI (source-diff): Minified React library code, standard bundler output. ai
source-diff obfuscated-file:public/assets/bootstrap-bNZv2cMS.js AI (source-diff): Vite/module-federation bundle output, not true obfuscation. ai
source-diff net-exec-file:public/assets/index-CHqwNyl4.js AI (source-diff): MF runtime uses new Function()/fetch internally; not exfil. ai
source-diff obfuscated-file:public/assets/index-C5SbDtSm.js AI (source-diff): Bundled React/vite output. ai
source-diff obfuscated-file:public/assets/index-BO-OvZjH.js AI (source-diff): Bundled React/vite output. ai
source-diff net-exec-file:public/assets/bootstrap-D-Os68-G.js AI (source-diff): Module Federation runtime loader pattern, not a dropper. ai
source-diff obfuscated-file:public/assets/bootstrap-D-Os68-G.js AI (source-diff): Vite/Module-Federation bundled output, not true obfuscation. ai
source-diff obfuscated-file:public/assets/index-CHqwNyl4.js AI (source-diff): Module Federation runtime bundle, not obfuscation. ai
source-diff net-exec-file:public/assets/bootstrap-CZMNYFm2.js AI (source-diff): Bundled React/websocket client code, not a dropper. ai
source-diff obfuscated-file:public/assets/bootstrap-CZMNYFm2.js AI (source-diff): Vite/webpack bundled frontend asset, not true obfuscation. ai
source-diff net-exec-file:public/assets/bootstrap-DhdGWh46.js AI (source-diff): Bundled frontend code with normal fetch/websocket usage, not a dropper. ai
source-diff obfuscated-file:public/assets/bootstrap-DhdGWh46.js AI (source-diff): Vite bundle output for React UI, not true obfuscation. ai
source-diff obfuscated-file:public/assets/index-DGNZrxCr.js AI (source-diff): Rollup-bundled React/scheduler code, minified not obfuscated. ai
source-diff obfuscated-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js AI (source-diff): Module-federation runtime bundle, minified not obfuscated. ai
source-diff net-exec-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js AI (source-diff): Bundled federation runtime; no exfil/dropper behavior found. ai
source-diff obfuscated-file:public/assets/bootstrap-CX1Fo5Ij.js AI (source-diff): Vite-bundled React app entry, minified build output. ai
source-diff net-exec-file:public/assets/bootstrap-CX1Fo5Ij.js AI (source-diff): Vite bundle; network/eval patterns are bundler runtime, not malicious. ai
source-diff net-exec-file:public/assets/bootstrap--2xek4Qw.js AI (source-diff): Vite bundle importing MF runtime, benign. ai
source-diff obfuscated-file:public/assets/bootstrap--2xek4Qw.js AI (source-diff): Vite-bundled entry file, minified not obfuscated. ai
source-diff net-exec-file:public/assets/bootstrap-Sl5eJoZ5.js AI (source-diff): Bundled frontend JS; network+eval patterns are React/bundler internals, not a dropper. ai
source-diff obfuscated-file:public/assets/bootstrap-Sl5eJoZ5.js AI (source-diff): Vite/rollup bundled build output, not true obfuscation. ai
source-diff net-exec-file:public/assets/bootstrap-NX_x-zUe.js AI (source-diff): Bundled React/UI code false-positives on network+eval heuristics; no concrete malicious behavior. ai
source-diff obfuscated-file:public/assets/bootstrap-NX_x-zUe.js AI (source-diff): Vite/rollup bundled webapp asset, matches declared build tooling, not true obfuscation. ai
source-diff obfuscated-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js AI (source-diff): Module Federation runtime bundle, minified not obfuscated malware. ai
source-diff net-exec-file:public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js AI (source-diff): Federation runtime loader; network+eval is its documented remote-module-loading function. ai
semgrep semgrep:eval-usage AI (semgrep): Inside Module Federation runtime's remote-loading logic, not injected code. ai
source-diff obfuscated-file:public/assets/index-5hkOWmYo.js AI (source-diff): React scheduler minified bundle. ai
source-diff obfuscated-file:public/assets/index-03avmwGu.js AI (source-diff): React production minified bundle. ai
source-diff net-exec-file:public/assets/bootstrap-Ca_bYwBS.js AI (source-diff): Bundled app entry, false positive from minified size. ai
source-diff obfuscated-file:public/assets/bootstrap-Ca_bYwBS.js AI (source-diff): Vite bundle output for React app entry, minified not malicious. ai
maintainer-change maintainer-removed AI (maintainer-change): Long-running project maintainer churn, publisher is trusted known maintainer. ai
bogus-package bogus-package AI (bogus-package): Established 8yr+ SignalK ecosystem package, metadata sparsity is not spam. ai
source-diff obfuscated-file:public/323.js AI (source-diff): Webpack bundle of app's own login/websocket code, not malicious obfuscation. ai
phantom-deps phantom-dep:zustand AI (phantom-deps): zustand is a declared runtime dependency; used in built output, not directly imported in source files scanned. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in bundled module federation runtime (remoteEntry.js); standard vite/webpack federation pattern, not malicious. ai

Versions (showing 25 of 25)

Version Deps Published
2.30.0 1 / 60
2.28.2 1 / 61
2.28.1 1 / 61
2.28.0 1 / 61
2.27.0 1 / 55
2.26.0 1 / 55
2.25.0 1 / 54
2.24.2 1 / 53
2.24.1 1 / 53
2.24.0 1 / 53
2.23.2 0 / 43
2.23.1 0 / 43
2.23.0 0 / 43
2.21.0 0 / 42
2.20.3 0 / 42
2.20.2 0 / 42
2.20.1 0 / 42
2.20.0 0 / 42
2.19.5 0 / 47
2.19.4 0 / 48
2.19.3 0 / 48
2.19.2 0 / 48
2.19.1 0 / 48
2.19.0 0 / 48
2.18.0 0 / 44

v2.30.0

3 findings
HIGH New obfuscated file: public/assets/bootstrap-CkVvyXgI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/bootstrap-CkVvyXgI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.28.2

3 findings
HIGH New obfuscated file: public/assets/bootstrap-CZMNYFm2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/bootstrap-CZMNYFm2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.23.2

8 findings
HIGH New obfuscated file: public/assets/bootstrap-bNZv2cMS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-bNZv2cMS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-BEQk0SN_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: public/assets/index-C0euSWDO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: public/assets/index.cjs-qNTcCtpj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/index.cjs-qNTcCtpj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-03-12, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-12, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.23.1

8 findings
HIGH New obfuscated file: public/assets/bootstrap-D-Os68-G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-D-Os68-G.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-BO-OvZjH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: public/assets/index-C5SbDtSm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: public/assets/index-CHqwNyl4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/index-CHqwNyl4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-03-08, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-08, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.23.0

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-OBqvctZP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap-CX1Fo5Ij.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-CX1Fo5Ij.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-DGNZrxCr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-03-03, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-03-03, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.21.0

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap-Dl8NOv2y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-Dl8NOv2y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-5hkOWmYo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-02-09, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-02-09, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.20.3

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap-Dl8NOv2y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-Dl8NOv2y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-5hkOWmYo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-02-09, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-02-09, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.20.2

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap-6CM60CZx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-6CM60CZx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-5hkOWmYo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-01-27, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-27, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.20.1

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap--2xek4Qw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap--2xek4Qw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-5hkOWmYo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-01-19, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-19, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.20.0

8 findings
HIGH New obfuscated file: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/assets/adminUI__mf_v__runtimeInit__mf_v__-Cm0AUItX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/assets/bootstrap-Ca_bYwBS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/assets/bootstrap-Ca_bYwBS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/assets/index-03avmwGu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/assets/index-5hkOWmYo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (rollup) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-01-18, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-18, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.19.5

3 findings
HIGH New obfuscated file: public/323.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-01-06, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-06, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.19.4

3 findings
HIGH New obfuscated file: public/323.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2026-01-01, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2026-01-01, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.19.3

3 findings
HIGH New obfuscated file: public/323.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2025-12-27, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2025-12-27, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.19.2

3 findings
HIGH New obfuscated file: public/323.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tkurki → sbender (on 2025-12-12, known maintainer) provenance

This version was published by a different npm account (sbender) than the most recent previously approved version (tkurki) on 2025-12-12, but sbender is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.