@stytch/nextjs
Stytch's official Next.js Library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs/shadcn-DgIkWX2p.js | AI (source-diff): Bundled UI component library, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-DXeJ6iFR.js | AI (source-diff): Bundled UI component library, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-Co1jziWL.js | AI (source-diff): Minified/bundled shadcn UI vendor chunk. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-B9XVRjLw.js | AI (source-diff): Minified/bundled shadcn UI vendor chunk. | ai | |
| source-diff | net-exec-file:dist/cjs-dev/adminPortal/index.cjs | AI (source-diff): False positive: bundled React library code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-Cc6xi2Yo.js | AI (source-diff): Bundled minified vendor code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/adminPortal/index.cjs | AI (source-diff): Bundled minified vendor/React code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/cjs/adminPortal/index.cjs | AI (source-diff): False positive: bundled React library code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-fk21FElT.js | AI (source-diff): Bundled minified vendor code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/adminPortal/index.cjs | AI (source-diff): Bundled minified vendor/React code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/types/createAuthUrlHandler-DIEnc3gq.d.ts | AI (source-diff): TypeScript declaration file with long import lines from bundled types; not obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): twilio-supply-chain reflects Stytch/Twilio org transition; consistent with legitimate corporate supply-chain account. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): jack-stytch removal is consistent with org-level account consolidation under Twilio ownership. | ai | |
| source-diff | obfuscated-file:dist/cjs-dev/shadcn-CR5Ys_AQ.js | AI (source-diff): Rollup-bundled output with readable code and comments; long lines are minified UI component code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/types/ui-DItv28jr.d.ts | AI (source-diff): Bundled .d.ts type declarations; long lines are concatenated type exports, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/cjs/shadcn-Dxlxo6v-.js | AI (source-diff): Same rollup bundle pattern; no encoded payloads or suspicious behavior. | ai | |
| typosquat | typosquat.levenshtein:next | AI (typosquat): Official Stytch Next.js SDK; name intentionally references Next.js, not a typosquat. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 22.0.10 | 0 / 18 | |
| 22.0.9 | 0 / 18 | |
| 22.0.8 | 0 / 18 | |
| 22.0.7 | 0 / 18 | |
| 22.0.6 | 0 / 18 | |
| 22.0.5 | 0 / 18 | |
| 22.0.4 | 0 / 18 | |
| 22.0.3 | 0 / 18 | |
| 22.0.0 | 0 / 18 | |
| 21.18.1 | 0 / 17 | |
| 21.18.0 | 0 / 17 | |
| 21.17.0 | 0 / 17 | |
| 21.16.0 | 0 / 17 | |
| 21.15.2 | 0 / 17 | |
| 21.15.1 | 0 / 17 |
v22.0.5
8 findingsThis version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v22.0.4
8 findingsThis version was published by a different npm account than previous versions on 2026-03-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v22.0.3
8 findingsThis version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v22.0.0
8 findingsThis version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.