← Home

@stytch/vanilla-js

18
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

marygruendanny-stytchyijiang-stytchjulianna-stytchreed-stytchgrace-stytchmax-stytchchris-stytchnicole-stytchjhaven-stytchtwilio-supply-chainjennifer-stytchnstam-stytchci-stytchsbracken

Keywords

stytchtypescriptauthauthenticationsessionjwtuser

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/iife/index.headless.js AI (source-diff): Rollup-minified SDK bundle, not obfuscation. ai
source-diff obfuscated-file:dist/iife/index.js AI (source-diff): Rollup-bundled dist output for official Stytch SDK; minified not obfuscated. ai
source-diff obfuscated-file:dist/iife/compat.js AI (source-diff): Minified rollup bundle (chroma-js), not obfuscation; stable for this SDK. ai
source-diff obfuscated-file:dist/cjs-dev/uniqueId-fcAegx4U.js AI (source-diff): Minified preact vendor code, not obfuscation. ai
source-diff obfuscated-file:dist/cjs/adminPortal/index.cjs AI (source-diff): Rollup-bundled dist output. ai
source-diff net-exec-file:dist/cjs/adminPortal/index.cjs AI (source-diff): Bundled SDK output; benign. ai
source-diff obfuscated-file:dist/cjs-dev/adminPortal/index.cjs AI (source-diff): Rollup-bundled dist output, readable source; not obfuscation. ai
source-diff net-exec-file:dist/cjs-dev/adminPortal/index.cjs AI (source-diff): Bundled SDK output; no hostile fetch/exec destination. ai
source-diff obfuscated-file:dist/cjs-dev/shadcn-Bzbol4Ww.js AI (source-diff): Bundled dist; readable annotated source. ai
source-diff obfuscated-file:dist/cjs/shadcn-CyIAo-yO.js AI (source-diff): Bundled dist; readable source. ai
source-diff large-new-source-files AI (source-diff): Build reorg for official SDK produces many dist files. ai
source-diff obfuscated-file:dist/cjs/uniqueId-DLJHPADm.js AI (source-diff): Minified preact vendor code. ai
source-diff net-exec-file:dist/extractErrorMessage-BXfvASmh.js AI (source-diff): Bundled auth-SDK fetch logic; benign for this package. ai
source-diff obfuscated-file:dist/extractErrorMessage-BXfvASmh.js AI (source-diff): Minified rollup/Babel build output, not obfuscation. ai
source-diff net-exec-file:dist/extractErrorMessage-CObjEQHE.js AI (source-diff): Bundled auth-SDK fetch logic. ai
source-diff obfuscated-file:dist/internal-xYwHZs2R.js AI (source-diff): Babel-helper minified build output. ai
source-diff obfuscated-file:dist/extractErrorMessage-CObjEQHE.js AI (source-diff): Minified build output. ai
source-diff net-exec-file:dist/extractErrorMessage-JkERx7rR.js AI (source-diff): Minified SDK bundle; benign. ai
source-diff obfuscated-file:dist/extractErrorMessage-DQKAgJ_9.js AI (source-diff): Minified rollup/babel build output, not obfuscation. ai
source-diff net-exec-file:dist/extractErrorMessage-DQKAgJ_9.js AI (source-diff): Minified SDK bundle; net+exec heuristic on normal build output. ai
source-diff obfuscated-file:dist/extractErrorMessage-JkERx7rR.js AI (source-diff): Minified rollup/babel build output. ai
source-diff obfuscated-file:dist/internal-GMeHquL-.js AI (source-diff): Babel helper minified output. ai
phantom-deps phantom-dep:@types/google-one-tap AI (phantom-deps): Types package loaded by convention. ai
source-diff obfuscated-file:dist/types/GoogleOneTapClient-BITSM9oM.d.ts AI (source-diff): TypeScript declaration file with long import lines; not obfuscated. ai
source-diff obfuscated-file:dist/types/DFPProtectedAuthProvider-DQV4qHPT.d.ts AI (source-diff): TypeScript declaration file with long import lines; not obfuscated. ai
source-diff obfuscated-file:dist/cjs-dev/shadcn-Dc0M3w2t.js AI (source-diff): Bundled build output with readable code; not obfuscated. ai
source-diff obfuscated-file:dist/cjs/shadcn-DbBiekGp.js AI (source-diff): Bundled build output with readable code; not obfuscated. ai
source-diff obfuscated-file:dist/cjs-dev/shadcn-C7p3HE31.js AI (source-diff): Minified build output from rollup bundler; code is readable and well-commented, not obfuscated. ai
source-diff obfuscated-file:dist/cjs/shadcn-DnwRqCY0.js AI (source-diff): Minified build output from rollup bundler; code is readable and well-commented, not obfuscated. ai

Versions (showing 18 of 18)

Version Deps Published
6.0.10 0 / 23
6.0.9 0 / 23
6.0.8 0 / 23
6.0.7 0 / 23
6.0.6 0 / 23
6.0.5 0 / 23
6.0.3 0 / 23
6.0.2 0 / 23
6.0.1 0 / 23
6.0.0 0 / 23
5.45.0 3 / 79
5.44.2 3 / 80
5.44.1 3 / 80
5.44.0 3 / 80
5.43.0 3 / 80
5.42.0 3 / 77
5.41.1 3 / 76
5.41.0 3 / 76

v6.0.5

17 findings
HIGH Publisher changed: ci-stytch → GitHub Actions (on 2026-03-19) provenance

This version was published by a different npm account than previous versions on 2026-03-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/compat.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/b2b/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/adminPortal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/iife/adminPortal/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/b2b/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/shadcn-DNo-Z1LB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/shadcn-JZgM-5AS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/uniqueId-D9puNTGE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/uniqueId-WccE1cND.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.3

17 findings
HIGH Publisher changed: ci-stytch → GitHub Actions (on 2026-02-27) provenance

This version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/compat.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/b2b/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/adminPortal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/iife/adminPortal/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/b2b/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/shadcn-BmPw6Q7O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/shadcn-Dqlb9O22.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/uniqueId-DLJHPADm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/uniqueId-fcAegx4U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.2

17 findings
HIGH Publisher changed: ci-stytch → GitHub Actions (on 2026-02-13) provenance

This version was published by a different npm account than previous versions on 2026-02-13. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/compat.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/b2b/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/adminPortal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/iife/adminPortal/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/b2b/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/shadcn-B3hvPKCt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/shadcn-DEJIbMOE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/uniqueId-DLJHPADm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/uniqueId-fcAegx4U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.1

17 findings
HIGH Publisher changed: ci-stytch → GitHub Actions (on 2026-02-11) provenance

This version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/compat.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/b2b/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.headless.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/adminPortal/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/iife/adminPortal/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/iife/b2b/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/iife/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/shadcn-Bzbol4Ww.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/shadcn-CyIAo-yO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/uniqueId-DLJHPADm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/uniqueId-fcAegx4U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.0

10 findings
HIGH Publisher changed: ci-stytch → GitHub Actions (on 2026-02-11) provenance

This version was published by a different npm account than previous versions on 2026-02-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs-dev/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs-dev/shadcn-Bzbol4Ww.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs-dev/uniqueId-fcAegx4U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/adminPortal/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cjs/adminPortal/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/cjs/shadcn-CyIAo-yO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cjs/uniqueId-DLJHPADm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.45.0

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-xYwHZs2R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.44.2

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-xYwHZs2R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.44.1

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-xYwHZs2R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.44.0

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-xYwHZs2R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.43.0

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-BXfvASmh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-CObjEQHE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-xYwHZs2R.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.42.0

6 findings
HIGH New obfuscated file: dist/extractErrorMessage-DQKAgJ_9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-DQKAgJ_9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/extractErrorMessage-JkERx7rR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/extractErrorMessage-JkERx7rR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/internal-GMeHquL-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.41.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.41.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.