@t2000/cli
A bank account for AI agents on Sui — guided setup, MCP integration, send, save, borrow, swap. Same 40 tools as the engine, scriptable from any shell.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/dist-BJOELEAN.js | AI (source-diff): Bundled MCP server with standard node/http imports, no fetched-binary behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-BJOELEAN.js | AI (source-diff): Minified bundled MCP server output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-EOFFFPZT.js | AI (source-diff): http/https imports are standard Node libs bundled by tsup for wallet networking, no dropper behavior observed. | ai | |
| source-diff | obfuscated-file:dist/dist-EOFFFPZT.js | AI (source-diff): Bundled tsup output with long minified lines, not true obfuscation; matches stated wallet/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-2LJUAYXZ.js | AI (source-diff): Main CLI bundle incl. MCP server; http/crypto imports are for RPC & wallet crypto, not exfil. | ai | |
| source-diff | obfuscated-file:dist/dist-2LJUAYXZ.js | AI (source-diff): tsup-bundled minified output with visible banner, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-B65MKNTC.js | AI (source-diff): Standard esbuild bundler preamble/shims, not an obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-B65MKNTC.js | AI (source-diff): Bundled MCP server + crypto for local key encryption, not a loader. | ai | |
| source-diff | obfuscated-file:dist/dist-SPX7DDL6.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-SPX7DDL6.js | AI (source-diff): Bundled CLI+MCP entry using node http/crypto for legit Sui RPC calls, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-VM6LUJ4I.js | AI (source-diff): Bundled MCP SDK output with standard node builtins; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-VM6LUJ4I.js | AI (source-diff): MCP SDK bundle uses http/crypto for legitimate server functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-SANXHUQ3.js | AI (source-diff): tsup-bundled MCP server code, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-SANXHUQ3.js | AI (source-diff): Bundled MCP server using Node builtins, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-OLK36LRI.js | AI (source-diff): tsup/esbuild bundle with long minified lines, not true obfuscation; no malicious payload shown. | ai | |
| source-diff | net-exec-file:dist/dist-OLK36LRI.js | AI (source-diff): Bundled MCP server code using standard node crypto/http/fs; matches stated CLI functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-OWOGTCZ6.js | AI (source-diff): Bundled Sui SDK code; network+dynamic exec expected for wallet RPC client, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-4WZIOWYY.js | AI (source-diff): tsup/esbuild bundle banner, not true obfuscation; matches @t2000/mcp source. | ai | |
| source-diff | net-exec-file:dist/dist-4WZIOWYY.js | AI (source-diff): Bundled MCP server code, dual-use APIs, no malicious destination evident. | ai | |
| source-diff | obfuscated-file:dist/dist-BSV6DAIB.js | AI (source-diff): Minified tsup bundle, not true obfuscation (no _0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/dist-BSV6DAIB.js | AI (source-diff): Bundled MCP server entry using Node core modules for CLI's own function. | ai | |
| source-diff | net-exec-file:dist/dist-U65BYMC5.js | AI (source-diff): Bundled MCP server with legitimate http/crypto usage, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-U65BYMC5.js | AI (source-diff): Minified bundle of MCP server code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-3VE5VEAA.js | AI (source-diff): Bundled MCP server using Node http/crypto; expected for stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-3VE5VEAA.js | AI (source-diff): tsup/esbuild bundle output (MCP server), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-MWHREDF2.js | AI (source-diff): Minified bundler output (long lines), not true obfuscation; no malicious payload shown. | ai | |
| source-diff | net-exec-file:dist/dist-MWHREDF2.js | AI (source-diff): Bundled MCP server code; crypto/http imports match documented CLI functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-4N76GQCL.js | AI (source-diff): Bundled Sui SDK code (tsup output), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-W4Q4YXD7.js | AI (source-diff): Bundled ajv/CLI code, network+exec pattern is normal for this tool. | ai | |
| source-diff | net-exec-file:dist/dist-XPK5WGV5.js | AI (source-diff): Bundled MCP server code, network+crypto use consistent with stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-XPK5WGV5.js | AI (source-diff): tsup/esbuild bundle output, matches bundler banner not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-UU3LLOLE.js | AI (source-diff): tsup/esbuild bundler output, not true obfuscation — standard minified preamble. | ai | |
| source-diff | net-exec-file:dist/dist-UU3LLOLE.js | AI (source-diff): Bundled MCP server module; http/crypto imports match stated wallet/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-7BWQQOS6.js | AI (source-diff): CLI wallet tool legitimately bundles network+crypto code; no exfil behavior shown. | ai | |
| source-diff | obfuscated-file:dist/dist-7BWQQOS6.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation; matches build banner pattern. | ai | |
| source-diff | net-exec-file:dist/dist-JCY6PNWP.js | AI (source-diff): Bundled network+crypto code expected for wallet CLI, no malicious behavior shown. | ai | |
| source-diff | obfuscated-file:dist/dist-JCY6PNWP.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-WYYARAJN.js | AI (source-diff): Bundled MCP server code (tsup output), not true obfuscation | ai | |
| source-diff | obfuscated-file:dist/dist-WYYARAJN.js | AI (source-diff): Minified bundler output, no _0x/eval-atob obfuscation signature | ai | |
| source-diff | obfuscated-file:dist/dist-O7YCMJB2.js | AI (source-diff): Bundled tsup output, not true obfuscation; contains normal deps. | ai | |
| source-diff | net-exec-file:dist/dist-O7YCMJB2.js | AI (source-diff): Bundled MCP integration code, standard node builtins, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/dist-F5JJ632B.js | AI (source-diff): Bundled MCP server with standard node/crypto/http imports, not a loader. | ai | |
| source-diff | obfuscated-file:dist/dist-F5JJ632B.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation; long lines are minification. | ai | |
| source-diff | obfuscated-file:dist/dist-KTARSG4H.js | AI (source-diff): tsup/esbuild bundled MCP server, long lines are build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KTARSG4H.js | AI (source-diff): Bundled MCP server with crypto/http/fs for wallet config storage, matches stated purpose. | ai | |
| source-diff | net-exec-file:dist/chunk-5LNVIJCB.js | AI (source-diff): Sui SDK bundle chunk; network+crypto is core wallet functionality, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-3QCDKKHZ.js | AI (source-diff): tsup/esbuild bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-3QCDKKHZ.js | AI (source-diff): Bundled MCP entrypoint; crypto/http imports are for wallet/MCP transport, not exfil. | ai | |
| source-diff | obfuscated-file:dist/dist-T5RV5ROR.js | AI (source-diff): tsup-bundled MCP server code, long lines from bundling not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-T5RV5ROR.js | AI (source-diff): Bundled MCP server with normal node builtins, no malicious behavior evidenced. | ai | |
| source-diff | net-exec-file:dist/dist-OJVTQZ23.js | AI (source-diff): Bundled MCP client with legit network/crypto usage for wallet CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-OJVTQZ23.js | AI (source-diff): Bundled MCP server code, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-Y4JGXERR.js | AI (source-diff): tsup/esbuild bundle with helper shims (__esm/__commonJS), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-Y4JGXERR.js | AI (source-diff): Same bundled MCP/SDK output; network calls are legitimate RPC usage. | ai | |
| source-diff | obfuscated-file:dist/dist-YCYX7NPI.js | AI (source-diff): tsup/esbuild bundle output (long lines from minification), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-YCYX7NPI.js | AI (source-diff): Bundled MCP server entrypoint; crypto/http usage matches documented CLI/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-JYCRPG45.js | AI (source-diff): Bundled Sui SDK chunk, part of normal wallet transaction handling. | ai | |
| source-diff | net-exec-file:dist/dist-57KQG4RN.js | AI (source-diff): Bundled MCP entrypoint output, matches package's stated MCP integration. | ai | |
| source-diff | obfuscated-file:dist/dist-57KQG4RN.js | AI (source-diff): tsup/esbuild bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/dist-XR34NKTX.js | AI (source-diff): tsup-bundled MCP server entry, standard build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-XR34NKTX.js | AI (source-diff): Same bundled MCP entry; require/crypto imports are legitimate deps, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-GXCNVMJX.js | AI (source-diff): Bundled MCP server code, tsup output with standard node builtins. | ai | |
| source-diff | obfuscated-file:dist/dist-GXCNVMJX.js | AI (source-diff): Long lines are minified bundler output, no true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-3TGAP6PT.js | AI (source-diff): Bundled ajv/commonjs shim in tsup output, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-OAYJYTLW.js | AI (source-diff): Long lines are tsup/esbuild bundling artifacts, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-OAYJYTLW.js | AI (source-diff): Bundled MCP server output; http/https imports are from bundled hono/node-server deps. | ai | |
| source-diff | obfuscated-file:dist/dist-EVKAQAUQ.js | AI (source-diff): tsup-bundled MCP server output, long lines from minification not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-EVKAQAUQ.js | AI (source-diff): Same bundled MCP output; no concrete malicious network target found. | ai | |
| source-diff | obfuscated-file:dist/dist-33NVE725.js | AI (source-diff): Bundled tsup/esbuild output, not obfuscation; long lines are minifier artifact. | ai | |
| source-diff | net-exec-file:dist/dist-33NVE725.js | AI (source-diff): Network+crypto imports match stated wallet/MCP functionality, no exfil behavior observed. | ai | |
| source-diff | net-exec-file:dist/dist-UONFI6HX.js | AI (source-diff): Bundled MCP index.js, network+crypto usage matches stated wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-UONFI6HX.js | AI (source-diff): Bundled MCP server code with crypto/http imports, standard for wallet CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-42T7ZGVN.js | AI (source-diff): tsup bundle with long lines; bundler minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-42T7ZGVN.js | AI (source-diff): Bundled MCP server code with standard node builtins, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-ZX4DO4GG.js | AI (source-diff): tsup-bundled MCP entrypoint, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-ZX4DO4GG.js | AI (source-diff): Bundled MCP server code, standard node builtins, no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-FBZWN6ED.js | AI (source-diff): Minified bundle output, not true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-FBZWN6ED.js | AI (source-diff): Minified bundle output including MCP integration code, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-UCB5RASG.js | AI (source-diff): tsup bundle of mcp/sdk sources, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-UCB5RASG.js | AI (source-diff): Bundled MCP server code w/ http libs; matches stated CLI/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-UJGH2XLF.js | AI (source-diff): Bundled ajv codegen + network deps via tsup, not a loader/dropper pattern. | ai | |
| source-diff | net-exec-file:dist/dist-EC5V2CMY.js | AI (source-diff): Bundled MCP client code; readable imports, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/dist-EC5V2CMY.js | AI (source-diff): Minified tsup bundle output, not true obfuscation (_0x/eval-atob). | ai | |
| source-diff | net-exec-file:dist/dist-Y2KV3PJT.js | AI (source-diff): Bundled MCP server code, inherent to package's stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-Y2KV3PJT.js | AI (source-diff): tsup bundler output, not true obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/dist-L7I3XOJK.js | AI (source-diff): tsup bundle banner/wrappers, not an obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/chunk-7MFY5PQG.js | AI (source-diff): Bundled Sui SDK chunk (RPC client), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-L7I3XOJK.js | AI (source-diff): Bundled MCP server entry, standard node builtins/imports. | ai | |
| source-diff | obfuscated-file:dist/dist-4LTAAGX3.js | AI (source-diff): Long lines are tsup/esbuild bundler output, no obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-4LTAAGX3.js | AI (source-diff): tsup-bundled MCP entrypoint with std node imports, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-ARDOW4B6.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation — no _0x/eval-atob pattern. | ai | |
| source-diff | net-exec-file:dist/dist-ARDOW4B6.js | AI (source-diff): Bundled MCP server code; http/crypto imports are core to package function. | ai | |
| source-diff | net-exec-file:dist/dist-3T3V2562.js | AI (source-diff): Bundled MCP entrypoint; dynamic require is bundler polyfill pattern. | ai | |
| source-diff | obfuscated-file:dist/dist-3T3V2562.js | AI (source-diff): tsup-bundled MCP/index.js output, long lines from bundling not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-BLG2ODOZ.js | AI (source-diff): Bundled MCP server code (tsup output), standard node builtins, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-BLG2ODOZ.js | AI (source-diff): Minified bundler output (tsup/esbuild banners), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-7FRW5BSS.js | AI (source-diff): Bundled MCP server code; network+crypto usage matches wallet CLI purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-7FRW5BSS.js | AI (source-diff): esbuild/tsup bundle output, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-LBQE6JNT.js | AI (source-diff): Bundled MCP/SDK code; http/crypto/fs used for legitimate wallet+RPC functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-LBQE6JNT.js | AI (source-diff): tsup bundle of MCP server, long lines are build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-6QF7QYS4.js | AI (source-diff): Bundled Sui SDK chunk; network+crypto usage matches wallet CLI's stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-UOMSU5UL.js | AI (source-diff): tsup bundle banner and readable var names; bundled not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-UOMSU5UL.js | AI (source-diff): Bundled MCP server entrypoint; standard tsup output, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-22NK522A.js | AI (source-diff): Bundled ajv/CLI code via tsup, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-JJCGJTSI.js | AI (source-diff): Bundled sui SDK code (tsup), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-4YHW4PXA.js | AI (source-diff): Bundled MCP server code using standard node http/crypto APIs, no malicious destination found. | ai | |
| source-diff | obfuscated-file:dist/dist-4YHW4PXA.js | AI (source-diff): tsup bundle output (long lines), not true obfuscation; matches wallet CLI's MCP/SDK bundling. | ai | |
| source-diff | obfuscated-file:dist/dist-LEDCCBZK.js | AI (source-diff): Long lines are tsup bundling artifacts, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-LEDCCBZK.js | AI (source-diff): Bundled MCP server output; http/crypto imports are the server's own function. | ai | |
| source-diff | net-exec-file:dist/dist-JF2T7VQK.js | AI (source-diff): Bundled ajv/tsup build output, not a real dropper; pattern-matched on minified library code. | ai | |
| source-diff | obfuscated-file:dist/dist-OECMFTLF.js | AI (source-diff): tsup/esbuild bundle output with banner, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-OECMFTLF.js | AI (source-diff): Bundled MCP server code (http/crypto), matches package purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-X4YUN6RA.js | AI (source-diff): tsup/esbuild bundle output, long lines not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-X4YUN6RA.js | AI (source-diff): Bundled MCP server code with standard node builtins, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-IBSI55JN.js | AI (source-diff): Bundled MCP module, standard build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-IBSI55JN.js | AI (source-diff): MCP server bundle uses http/crypto as part of stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-SLM2OSSP.js | AI (source-diff): tsup-minified dist, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-SLM2OSSP.js | AI (source-diff): Bundled MCP/wallet CLI output; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-KDR2GPAB.js | AI (source-diff): Bundled Sui SDK dist output; net+require is build artifact, not dropper. | ai | |
| source-diff | net-exec-file:dist/dist-HPXLVXU7.js | AI (source-diff): Same bundled MCP dist file; standard imports, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-HPXLVXU7.js | AI (source-diff): Minified bundler output (tsup/esbuild helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-EDKKAGYS.js | AI (source-diff): MCP server needs http/crypto for its documented functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-EDKKAGYS.js | AI (source-diff): Bundled MCP server code, standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/dist-WBEDB2PC.js | AI (source-diff): Minified bundle (long lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-WBEDB2PC.js | AI (source-diff): Bundled MCP/SDK output, tsup build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-T6CNV6SL.js | AI (source-diff): Bundled MCP server code with node crypto for local key mgmt, matches wallet function. | ai | |
| source-diff | obfuscated-file:dist/dist-T6CNV6SL.js | AI (source-diff): tsup-bundled MCP module, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-6UD6X4ER.js | AI (source-diff): Bundled MCP dist output; standard build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-6UD6X4ER.js | AI (source-diff): Bundled MCP dist output using node crypto/http per stated CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-LZGRHEQB.js | AI (source-diff): tsup bundle output with standard build helpers, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-LZGRHEQB.js | AI (source-diff): Bundled MCP module code, matches package's stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-6WQXS53W.js | AI (source-diff): Bundled MCP server code; matches package's stated MCP integration feature. | ai | |
| source-diff | net-exec-file:dist/dist-6WQXS53W.js | AI (source-diff): Bundled MCP server with standard node network modules, no exfil behavior shown. | ai | |
| source-diff | net-exec-file:dist/chunk-V5GSOFGJ.js | AI (source-diff): Bundled aggregator/RPC client chunk, standard SDK network code. | ai | |
| source-diff | obfuscated-file:dist/dist-TUAS5C2A.js | AI (source-diff): Bundled MCP server entry, standard requires/crypto imports, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-TUAS5C2A.js | AI (source-diff): MCP server bundle uses http/crypto normally for its stated function. | ai | |
| source-diff | net-exec-file:dist/dist-3YQCGTM3.js | AI (source-diff): Bundled MCP server chunk with standard node/crypto imports, not a loader. | ai | |
| source-diff | obfuscated-file:dist/dist-3YQCGTM3.js | AI (source-diff): tsup/esbuild bundler banner and minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-VSQDPVE5.js | AI (source-diff): tsup/esbuild minified bundle, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-VSQDPVE5.js | AI (source-diff): Bundled Sui/MCP client output; http+RPC is core function, no hostile target. | ai | |
| source-diff | net-exec-file:dist/dist-YOLTTLD3.js | AI (source-diff): Bundled MCP server using standard node builtins, no exfil target. | ai | |
| source-diff | obfuscated-file:dist/dist-YOLTTLD3.js | AI (source-diff): tsup-bundled MCP server code, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-SUGJ4KRH.js | AI (source-diff): Same bundled MCP file; network/crypto imports match stated wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-SUGJ4KRH.js | AI (source-diff): Bundled MCP server output, standard bundler banner/minification. | ai | |
| source-diff | net-exec-file:dist/dist-S4OOC4XZ.js | AI (source-diff): Bundled tsup output containing ajv codegen; no malicious payload, matches CLI's stated network/wallet function. | ai | |
| source-diff | net-exec-file:dist/dist-FR3EHQIM.js | AI (source-diff): Bundled MCP server code; standard http/crypto usage for stated CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-FR3EHQIM.js | AI (source-diff): tsup bundler output with require/commonjs shims, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-DL27EDPL.js | AI (source-diff): Bundled MCP server code; network+crypto expected for MCP tool. | ai | |
| source-diff | obfuscated-file:dist/dist-DL27EDPL.js | AI (source-diff): tsup bundler output of @t2000/mcp, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-B7O5FUPB.js | AI (source-diff): Bundled MCP entrypoint code, legitimate network/fs usage for CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-B7O5FUPB.js | AI (source-diff): Minified bundle (tsup), no true obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/dist-RDDTPYWM.js | AI (source-diff): tsup/esbuild bundler banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-RDDTPYWM.js | AI (source-diff): Bundled MCP server entry; http/crypto imports match stated MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-7DTUM5MT.js | AI (source-diff): Bundled MCP server entry with node crypto/http, matches stated CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-7DTUM5MT.js | AI (source-diff): tsup/esbuild bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-MBNGFMZQ.js | AI (source-diff): Bundled Sui SDK chunk (bignumber.js etc), not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-OBNLH7CK.js | AI (source-diff): Bundled MCP SDK using node http/https/crypto, no fetched-binary or exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-OBNLH7CK.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation; contains standard Node core imports. | ai | |
| source-diff | obfuscated-file:dist/dist-O4CDWCCM.js | AI (source-diff): Bundled MCP server output, standard bundler shim code. | ai | |
| source-diff | net-exec-file:dist/dist-O4CDWCCM.js | AI (source-diff): Bundled MCP server exposing crypto/network APIs, matches package purpose. | ai | |
| source-diff | net-exec-file:dist/dist-VBMR5MD5.js | AI (source-diff): Bundled MCP dist code, network/crypto imports are legitimate deps. | ai | |
| source-diff | obfuscated-file:dist/dist-VBMR5MD5.js | AI (source-diff): tsup bundle output (long lines), matches MCP integration source. | ai | |
| source-diff | net-exec-file:dist/chunk-LE7LKEOJ.js | AI (source-diff): Bundled @mysten/sui SDK code; RPC calls are core wallet functionality, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/dist-4FXGI3TM.js | AI (source-diff): Bundled ajv/schema validation code shipped with SDK; not a loader. | ai | |
| source-diff | net-exec-file:dist/dist-EKE6HYA2.js | AI (source-diff): tsup-bundled MCP entrypoint; dynamic require shim is bundler boilerplate. | ai | |
| source-diff | obfuscated-file:dist/dist-EKE6HYA2.js | AI (source-diff): tsup bundle output, long lines from minification. | ai | |
| source-diff | net-exec-file:dist/chunk-7PIRCLKI.js | AI (source-diff): Bundled Sui SDK chunk (tsup output), not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-NREODDWO.js | AI (source-diff): Bundled ajv/codegen dependency chunk, standard tsup output. | ai | |
| source-diff | net-exec-file:dist/dist-4BEL3XUI.js | AI (source-diff): MCP server bundle uses http/crypto legitimately for wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-4BEL3XUI.js | AI (source-diff): Bundled MCP module, standard esbuild shim pattern. | ai | |
| source-diff | net-exec-file:dist/dist-72VBXJ3I.js | AI (source-diff): Bundled MCP server with crypto/http imports matching stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-72VBXJ3I.js | AI (source-diff): tsup-bundled MCP server code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-HF73WWOL.js | AI (source-diff): Bundled MCP server code using crypto/http for wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-HF73WWOL.js | AI (source-diff): Bundled build output, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/chunk-5MIJ3Y2T.js | AI (source-diff): Bundled Sui SDK client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-QHCQQBPF.js | AI (source-diff): Bundled esbuild/tsup output of Sui SDK/MCP deps, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-QHCQQBPF.js | AI (source-diff): Standard node builtins (http/https/crypto) bundled from MCP/SDK, no malicious behavior found. | ai | |
| source-diff | net-exec-file:dist/dist-6RCPRF6H.js | AI (source-diff): Bundled MCP server code with standard node http/crypto imports, no malicious target. | ai | |
| source-diff | obfuscated-file:dist/dist-6RCPRF6H.js | AI (source-diff): tsup/esbuild bundle output (long lines from bundling), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-WZZLBHFT.js | AI (source-diff): Long lines are tsup/esbuild bundling artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-WZZLBHFT.js | AI (source-diff): Bundled MCP server code (tsup output), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-HNUMPYQX.js | AI (source-diff): Bundled ajv/hono code (tsup output), not injected dropper logic per sample. | ai | |
| source-diff | obfuscated-file:dist/dist-UJYWSEPW.js | AI (source-diff): tsup bundler output; standard commonJS/esm interop shims, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UJYWSEPW.js | AI (source-diff): Bundled MCP server entrypoint using standard node http/crypto modules. | ai | |
| source-diff | net-exec-file:dist/dist-4MZRTJCP.js | AI (source-diff): Bundled MCP server code with standard node builtins, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-4MZRTJCP.js | AI (source-diff): Bundled output, no obfuscation signature present. | ai | |
| source-diff | obfuscated-file:dist/dist-ZPDQE4TU.js | AI (source-diff): Bundled build artifact from tsup, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/dist-ZPDQE4TU.js | AI (source-diff): Bundled MCP server entry using standard http/crypto modules; not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-BVJI5QD5.js | AI (source-diff): Bundled MCP server code with expected network/crypto usage. | ai | |
| source-diff | obfuscated-file:dist/dist-BVJI5QD5.js | AI (source-diff): Bundled MCP/crypto code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-PWUMERAR.js | AI (source-diff): Bundled MCP server module, network+crypto usage is core functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-PWUMERAR.js | AI (source-diff): tsup bundler output including MCP server code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-5K5CVEOT.js | AI (source-diff): Bundled MCP server dist, standard esbuild/tsup boilerplate. | ai | |
| source-diff | net-exec-file:dist/dist-5K5CVEOT.js | AI (source-diff): Bundled MCP index using node http/crypto for wallet operations, expected. | ai | |
| source-diff | obfuscated-file:dist/dist-ZNCQCTB2.js | AI (source-diff): tsup/esbuild bundled output with __commonJS/__esm helpers, standard bundler artifact. | ai | |
| source-diff | net-exec-file:dist/dist-ZNCQCTB2.js | AI (source-diff): Bundled MCP server code with standard crypto/http usage, not malicious loader. | ai | |
| source-diff | net-exec-file:dist/chunk-HMCFZXVY.js | AI (source-diff): Bundled Sui SDK RPC client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-GBPSZNJO.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-GBPSZNJO.js | AI (source-diff): Bundled MCP server code with normal node builtins, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-V64TUY25.js | AI (source-diff): Bundled MCP/CLI code using http/https legitimately for wallet API calls. | ai | |
| source-diff | obfuscated-file:dist/dist-V64TUY25.js | AI (source-diff): tsup bundle output (long minified lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-RWDYR67F.js | AI (source-diff): Bundled ajv/schema validation code within tsup output. | ai | |
| source-diff | net-exec-file:dist/chunk-CEYH4WJI.js | AI (source-diff): Bundled @mysten/sui code; RPC calls are the SDK's normal function. | ai | |
| source-diff | net-exec-file:dist/chunk-ZH6PX6WS.js | AI (source-diff): Sui RPC client bundle; network+eval patterns are normal for blockchain SDK bundling. | ai | |
| source-diff | net-exec-file:dist/dist-NH7XYB4F.js | AI (source-diff): CLI+MCP entrypoint bundle; network/crypto imports match wallet's stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-NH7XYB4F.js | AI (source-diff): tsup bundle of CLI+MCP entrypoint; long lines from bundler, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-O4WYNOSR.js | AI (source-diff): Bundled MCP server code; not a dropper/loader pattern. | ai | |
| source-diff | obfuscated-file:dist/dist-O4WYNOSR.js | AI (source-diff): tsup-bundled build output, long minified lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-IBS23LR5.js | AI (source-diff): Bundled MCP server using http/https, expected for MCP integration feature. | ai | |
| source-diff | obfuscated-file:dist/dist-IBS23LR5.js | AI (source-diff): Bundled/minified tsup output (MCP+SDK code), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-APKOY2VV.js | AI (source-diff): tsup bundle output including MCP server; crypto/http imports are standard, not exfil. | ai | |
| source-diff | obfuscated-file:dist/dist-APKOY2VV.js | AI (source-diff): tsup bundle output, standard minification artifact. | ai | |
| source-diff | net-exec-file:dist/dist-D7SMKZQX.js | AI (source-diff): Bundled MCP SDK output with crypto/net used for wallet ops. | ai | |
| source-diff | obfuscated-file:dist/dist-D7SMKZQX.js | AI (source-diff): Bundled MCP SDK output, matches CLI's documented function. | ai | |
| source-diff | net-exec-file:dist/dist-5GFHWHSY.js | AI (source-diff): Bundled ajv validation code, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-IFUEUS6Y.js | AI (source-diff): Bundled poseidon-lite/crypto lib code, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-OMYCTHXH.js | AI (source-diff): tsup-bundled MCP/CLI code, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-OMYCTHXH.js | AI (source-diff): Bundled MCP server code with standard node http/crypto imports. | ai | |
| source-diff | obfuscated-file:dist/dist-ZVP4KBUD.js | AI (source-diff): tsup-bundled MCP output with long lines; no true obfuscation signature present. | ai | |
| source-diff | net-exec-file:dist/dist-ZVP4KBUD.js | AI (source-diff): Bundled MCP server code; http/crypto imports match stated CLI/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-KVEHGTYJ.js | AI (source-diff): Bundled MCP server with standard http/https imports, no dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/dist-KVEHGTYJ.js | AI (source-diff): Bundled tsup/esbuild output (MCP+SDK), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-5VJWN7TU.js | AI (source-diff): Bundled MCP dist output; imports are standard Node libs, no exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-5VJWN7TU.js | AI (source-diff): tsup-bundled MCP server, long minified lines not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-MKAGQFR3.js | AI (source-diff): Bundled ajv codegen module, not a dropper; standard tsup bundle output. | ai | |
| source-diff | obfuscated-file:dist/dist-GFSZZXA7.js | AI (source-diff): Bundled build output with readable helper functions, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunk-5GDUQVB4.js | AI (source-diff): Bundled Sui SDK/RPC client code, not a loader; net+exec is the wallet's core function. | ai | |
| source-diff | net-exec-file:dist/dist-GFSZZXA7.js | AI (source-diff): Bundled MCP server entrypoint; standard http/crypto imports for wallet CLI. | ai | |
| source-diff | net-exec-file:dist/dist-3PYU4RZC.js | AI (source-diff): Bundled MCP server code; network/crypto usage matches stated wallet+MCP functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-3PYU4RZC.js | AI (source-diff): tsup/esbuild bundle output, long lines from minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-7Z3BRR5Z.js | AI (source-diff): tsup-bundled MCP entrypoint; long minified lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-7Z3BRR5Z.js | AI (source-diff): Same bundled file; standard Node builtins, matches CLI's documented function. | ai | |
| source-diff | obfuscated-file:dist/dist-M7PSITSX.js | AI (source-diff): Bundled tsup/esbuild output with long lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-M7PSITSX.js | AI (source-diff): Standard node http/https/crypto imports in bundled MCP/SDK code, matches wallet CLI purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-GLXYR6HD.js | AI (source-diff): tsup-bundled MCP/CLI code, long lines from minification not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-GLXYR6HD.js | AI (source-diff): Bundled MCP server code; network/crypto use matches wallet CLI's stated purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-KSM6HRB2.js | AI (source-diff): Long lines are minified bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KSM6HRB2.js | AI (source-diff): Bundled MCP server code, not a dropper/loader. | ai | |
| source-diff | obfuscated-file:dist/dist-QYF5WAPE.js | AI (source-diff): tsup/esbuild bundle output (long lines), not true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-QYF5WAPE.js | AI (source-diff): Bundled MCP server code; http/crypto usage matches documented functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-4W7T24L5.js | AI (source-diff): Bundled Sui SDK code; network+crypto imports match package's stated wallet/RPC function. | ai | |
| source-diff | net-exec-file:dist/dist-6USY6KES.js | AI (source-diff): tsup-bundled MCP server entry; imports are standard node builtins. | ai | |
| source-diff | obfuscated-file:dist/dist-6USY6KES.js | AI (source-diff): Minified tsup bundle, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-G4HFQNSF.js | AI (source-diff): tsup bundle output (long lines from bundler), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-G4HFQNSF.js | AI (source-diff): Bundled MCP/SDK code; network+exec calls are the tool's own Sui RPC functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-VMYL2LVD.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-VMYL2LVD.js | AI (source-diff): Bundled MCP server entrypoint; standard node core imports, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-5CC44TXN.js | AI (source-diff): tsup/esbuild bundle output with standard build-tool helpers. | ai | |
| source-diff | net-exec-file:dist/dist-5CC44TXN.js | AI (source-diff): Bundled MCP server output, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-RQA6LP4F.js | AI (source-diff): Bundled dependency code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-XNKVJ4IY.js | AI (source-diff): Bundled dependency code (ajv/sui sdk), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-NPNSPZLJ.js | AI (source-diff): Minified bundler output (long lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-NPNSPZLJ.js | AI (source-diff): tsup/esbuild bundle output; network+crypto imports match Sui RPC/wallet function. | ai | |
| source-diff | obfuscated-file:dist/dist-Z5RIIMPE.js | AI (source-diff): Long lines are tsup/esbuild bundling artifacts, not true obfuscation (no _0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/dist-Z5RIIMPE.js | AI (source-diff): Bundled MCP server code; http/crypto imports match stated wallet/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-7MV3I2I7.js | AI (source-diff): Bundled MCP server code; standard Node builtins, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-7MV3I2I7.js | AI (source-diff): tsup bundle output (long lines from bundling), no true obfuscation signature present. | ai | |
| source-diff | net-exec-file:dist/chunk-VHEK2AU4.js | AI (source-diff): Bundled Sui SDK client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-IG6KJCZ4.js | AI (source-diff): Bundled MCP SDK output, standard tsup banner. | ai | |
| source-diff | net-exec-file:dist/dist-IG6KJCZ4.js | AI (source-diff): Bundled MCP SDK output, no malicious network target. | ai | |
| source-diff | net-exec-file:dist/dist-MUACHOIR.js | AI (source-diff): Bundled ajv codegen module, not a loader/dropper; standard tsup bundling artifact. | ai | |
| source-diff | obfuscated-file:dist/dist-ULTRYNV7.js | AI (source-diff): tsup/esbuild bundle output (MCP integration), long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-ULTRYNV7.js | AI (source-diff): Bundled MCP module using node http/https, matches package's stated MCP integration. | ai | |
| source-diff | net-exec-file:dist/chunk-64M2IV26.js | AI (source-diff): Bundled Sui SDK code (bignumber.js etc), not a loader; net+eval flags are bundler artifacts. | ai | |
| source-diff | obfuscated-file:dist/dist-A4EDABPU.js | AI (source-diff): tsup bundle, minified/long-line but not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-A4EDABPU.js | AI (source-diff): tsup-bundled MCP server entry, normal node builtins usage. | ai | |
| source-diff | net-exec-file:dist/dist-HFB2G5PO.js | AI (source-diff): Bundled MCP server chunk; network use matches package's stated MCP integration. | ai | |
| source-diff | obfuscated-file:dist/dist-HFB2G5PO.js | AI (source-diff): Bundled tsup output (long minified lines), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-JCTVXG6T.js | AI (source-diff): Minified bundler output (MCP server bundle), not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-JCTVXG6T.js | AI (source-diff): Bundled MCP server code with standard node builtins, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-JHT7EXQL.js | AI (source-diff): Bundled Sui SDK/ajv code, not a dropper; tsup output triggers pattern-match falsely. | ai | |
| source-diff | net-exec-file:dist/dist-ZKLEFNJE.js | AI (source-diff): Bundled dependency code (ajv/zod), not attacker-injected exec. | ai | |
| source-diff | obfuscated-file:dist/dist-6X4RKSUE.js | AI (source-diff): Minified bundle (esbuild helpers, long lines) not true obfuscation; matches bundled MCP dist. | ai | |
| source-diff | net-exec-file:dist/dist-6X4RKSUE.js | AI (source-diff): Bundled MCP server code; http/crypto imports fit stated CLI+MCP functionality. | ai | |
| source-diff | net-exec-file:dist/dist-23HNABJP.js | AI (source-diff): Bundled MCP entrypoint, matches package's stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-23HNABJP.js | AI (source-diff): Minified bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-QZEXNSBG.js | AI (source-diff): Bundled aggregator/RPC client chunk, standard bundler output. | ai | |
| source-diff | net-exec-file:dist/chunk-75SPBSDU.js | AI (source-diff): Bundled Sui SDK chunk (tsup output), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-MUFB2EMR.js | AI (source-diff): Bundled MCP SDK using node http/crypto normally; not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-MUFB2EMR.js | AI (source-diff): Bundled MCP SDK entry; minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-TWHMO32B.js | AI (source-diff): Minified bundler output, no true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-TWHMO32B.js | AI (source-diff): tsup-bundled MCP server output, not malicious loader. | ai | |
| source-diff | net-exec-file:dist/dist-PN7VN6JK.js | AI (source-diff): Bundled MCP/CLI entry, standard node built-ins for a wallet CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-PN7VN6JK.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-TVXO4LMR.js | AI (source-diff): Bundled MCP module; standard node core imports, not a loader. | ai | |
| source-diff | obfuscated-file:dist/dist-TVXO4LMR.js | AI (source-diff): tsup bundle output with long lines; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KJM2NT74.js | AI (source-diff): Bundled ajv/CLI code (tsup output), no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/chunk-3WKGZRWT.js | AI (source-diff): Bundled Sui SDK code (tsup output), no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/dist-TBNLSHE6.js | AI (source-diff): Bundled ajv/commonjs shim via tsup, not a dropper; network+eval pattern is build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-5EASN5MD.js | AI (source-diff): Bundled MCP server code using Node core http/crypto, expected for stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-5EASN5MD.js | AI (source-diff): tsup-bundled MCP integration output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-ZYPYPQ24.js | AI (source-diff): Bundled MCP entrypoint; network+exec matches CLI/MCP server function. | ai | |
| source-diff | obfuscated-file:dist/dist-ZYPYPQ24.js | AI (source-diff): tsup bundler output with long lines, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-NRRLXXSG.js | AI (source-diff): Bundled build output with standard bundler preamble. | ai | |
| source-diff | net-exec-file:dist/dist-NRRLXXSG.js | AI (source-diff): Bundled MCP server entry code, expected for CLI/MCP tool. | ai | |
| source-diff | obfuscated-file:dist/dist-XSNNKQQN.js | AI (source-diff): tsup bundle output with long lines; standard shims, not real obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-XSNNKQQN.js | AI (source-diff): Bundled MCP server code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-4JZ33TE5.js | AI (source-diff): Bundled MCP server code with standard node builtins; matches CLI's network function. | ai | |
| source-diff | obfuscated-file:dist/dist-4JZ33TE5.js | AI (source-diff): tsup bundle of MCP integration; long lines are minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-YKME3ZZ5.js | AI (source-diff): Bundled Sui SDK code (bignumber.js, chunk imports); no malicious payload evident. | ai | |
| source-diff | obfuscated-file:dist/esm-EIRCX523.js | AI (source-diff): Bundled crypto libs (poseidon-lite) for Sui wallet; build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-P7SWDSUQ.js | AI (source-diff): Long lines are tsup bundler output (MCP server bundle), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-P7SWDSUQ.js | AI (source-diff): Bundled MCP server with legit http/crypto usage, consistent with stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-YQVSOKNX.js | AI (source-diff): tsup-bundled MCP server, long minified lines not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-YQVSOKNX.js | AI (source-diff): Same bundled MCP server file; legitimate http/https usage for CLI's stated function. | ai | |
| source-diff | net-exec-file:dist/dist-H6MWADWT.js | AI (source-diff): Bundled MCP server code with standard node builtins, not malicious exec. | ai | |
| source-diff | obfuscated-file:dist/dist-H6MWADWT.js | AI (source-diff): Minified bundled MCP/SDK output, no true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/chunk-YZ6UELLB.js | AI (source-diff): Bundled Sui SDK RPC client code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-SPZX35RD.js | AI (source-diff): Bundled ajv/dependency code, legitimate build output. | ai | |
| source-diff | net-exec-file:dist/dist-KHZBBHJF.js | AI (source-diff): MCP server bundle; crypto/http imports are core to wallet CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-KHZBBHJF.js | AI (source-diff): Bundled MCP SDK output; long lines from tsup minification. | ai | |
| source-diff | net-exec-file:dist/chunk-JDOIQPNR.js | AI (source-diff): Bundled Sui SDK chunk; network/exec calls are library RPC code, not injected. | ai | |
| source-diff | obfuscated-file:dist/dist-PMYELDIE.js | AI (source-diff): tsup-bundled MCP SDK output; long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-PMYELDIE.js | AI (source-diff): Same bundled MCP SDK file; node http/crypto imports are standard, no exfil behavior shown. | ai | |
| source-diff | net-exec-file:dist/dist-QE7NG5LG.js | AI (source-diff): Bundled MCP integration code, network+fs use matches stated CLI function. | ai | |
| source-diff | net-exec-file:dist/chunk-UJGE644R.js | AI (source-diff): Bundled Sui SDK chunk, not a loader; imports are normal crypto/blockchain libs. | ai | |
| source-diff | obfuscated-file:dist/dist-QE7NG5LG.js | AI (source-diff): tsup bundle output (long lines), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm-ZKAIHFAJ.js | AI (source-diff): Bundled crypto lib (poseidon-lite), not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/dist-6BUCP4LO.js | AI (source-diff): Bundled @t2000/mcp entrypoint, standard bundler output. | ai | |
| source-diff | net-exec-file:dist/dist-6BUCP4LO.js | AI (source-diff): MCP server bundle uses http/crypto normally for its stated function. | ai | |
| source-diff | obfuscated-file:dist/src-FIYSHJR4.js | AI (source-diff): tsup bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-TCGFVCLO.js | AI (source-diff): tsup bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm-ORCGSDY7.js | AI (source-diff): tsup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-3TZXRO3E.js | AI (source-diff): Bundled Sui SDK code, standard imports not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-TCGFVCLO.js | AI (source-diff): Bundled MCP/CLI entry, standard node builtins not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-F547FLRR.js | AI (source-diff): Minified bundle output with standard imports, no obfuscation signatures. | ai | |
| source-diff | net-exec-file:dist/dist-F547FLRR.js | AI (source-diff): Bundled MCP server code for wallet CLI, network/crypto use matches stated function. | ai | |
| source-diff | net-exec-file:dist/dist-HNGOYWVQ.js | AI (source-diff): Main bundled entry (tsup/esbuild output) with standard Node builtins, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-HNGOYWVQ.js | AI (source-diff): Bundled build artifact, standard bundler preamble. | ai | |
| source-diff | net-exec-file:dist/chunk-XQSJMXDP.js | AI (source-diff): Bundled aggregator client chunk; standard tsup output. | ai | |
| source-diff | obfuscated-file:dist/dist-5O3HO6YP.js | AI (source-diff): tsup/esbuild bundle artifact, consistent with build scripts in package.json. | ai | |
| source-diff | net-exec-file:dist/dist-5O3HO6YP.js | AI (source-diff): Main CLI bundle; imports match documented MCP/CLI functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-L6CQW3XK.js | AI (source-diff): Bundled Sui SDK code, not a dropper; standard library exports visible in sample. | ai | |
| source-diff | net-exec-file:dist/dist-T2QOLDAP.js | AI (source-diff): Bundled ajv/commonjs code, benign build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-NZPBVOV6.js | AI (source-diff): Bundled MCP server code; network/crypto imports match stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-NZPBVOV6.js | AI (source-diff): tsup bundle output (long lines, __commonJS/__esm helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-UTSUSZ5R.js | AI (source-diff): tsup bundle output with long lines; standard build helpers, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UTSUSZ5R.js | AI (source-diff): Bundled MCP server code; crypto/http usage matches stated agent-wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-TUASOKZM.js | AI (source-diff): tsup-bundled MCP SDK output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-TUASOKZM.js | AI (source-diff): Bundled MCP server code using standard node http/crypto modules. | ai | |
| source-diff | net-exec-file:dist/dist-UPUBYGXT.js | AI (source-diff): Bundled MCP server using http/https for legitimate RPC, matches package purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-UPUBYGXT.js | AI (source-diff): tsup/esbuild bundle of MCP server code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-TQAM6VEU.js | AI (source-diff): Bundled MCP entrypoint; crypto/http imports match package's stated wallet/RPC function. | ai | |
| source-diff | obfuscated-file:dist/dist-TQAM6VEU.js | AI (source-diff): tsup bundle output (long lines), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-5NFFEQSF.js | AI (source-diff): tsup/esbuild bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-5NFFEQSF.js | AI (source-diff): tsup-bundled MCP server entrypoint; matches package's documented function. | ai | |
| source-diff | net-exec-file:dist/dist-MNRVFCYH.js | AI (source-diff): tsup bundle entrypoint; matches package's stated wallet/MCP function. | ai | |
| source-diff | obfuscated-file:dist/dist-MNRVFCYH.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KAYOSIOG.js | AI (source-diff): Bundled dependency code (ajv codegen), not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-KLHAR3XK.js | AI (source-diff): Bundled dependency code (ajv/sui SDK), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-3RLXPNZ5.js | AI (source-diff): Bundled ajv library code inside tsup build output, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-MKAGVSAK.js | AI (source-diff): Bundled tsup/esbuild output of Sui SDK/MCP, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-MKAGVSAK.js | AI (source-diff): Bundled MCP server code with normal fs/http usage for wallet CLI. | ai | |
| source-diff | net-exec-file:dist/chunk-COE5RRNH.js | AI (source-diff): Bundled Sui SDK client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-7TDENFJA.js | AI (source-diff): Bundled MCP server code, tsup output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-7TDENFJA.js | AI (source-diff): MCP server RPC/crypto usage matches stated wallet functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-J7X23P3A.js | AI (source-diff): Bundled Sui SDK chunk; network/crypto imports match wallet CLI functionality, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-CEF2K35K.js | AI (source-diff): Bundled MCP server code; standard node builtins for CLI/server, not exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-CEF2K35K.js | AI (source-diff): tsup/esbuild bundler output with long lines, not true obfuscation (no _0x/eval-atob patterns). | ai | |
| source-diff | obfuscated-file:dist/dist-UHRQXWYX.js | AI (source-diff): Minified bundle (long lines from build), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UHRQXWYX.js | AI (source-diff): Bundled MCP/CLI code using stdlib http/crypto; no malicious network target found. | ai | |
| source-diff | net-exec-file:dist/dist-XXZUATSX.js | AI (source-diff): Bundled MCP server entry, legitimate use of http/crypto for wallet CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-XXZUATSX.js | AI (source-diff): Long minified lines from tsup bundling, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-J6TJ4ITA.js | AI (source-diff): tsup/esbuild bundle artifact (long lines, __commonJS helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-J6TJ4ITA.js | AI (source-diff): Bundled MCP server code; http/crypto imports fit package purpose. | ai | |
| source-diff | net-exec-file:dist/dist-G243RVHJ.js | AI (source-diff): tsup-bundled MCP/CLI entry with crypto+http imports, expected for this package. | ai | |
| source-diff | obfuscated-file:dist/dist-G243RVHJ.js | AI (source-diff): Minified bundler output (long lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-Z7ZZOOWM.js | AI (source-diff): tsup-bundled MCP/CLI entry; network/crypto imports match stated wallet CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-Z7ZZOOWM.js | AI (source-diff): tsup bundle banner visible; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-7UBR5NVL.js | AI (source-diff): tsup bundle of MCP server; standard bundler boilerplate, no malicious payload shown. | ai | |
| source-diff | obfuscated-file:dist/dist-7UBR5NVL.js | AI (source-diff): tsup/esbuild bundle output, standard minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-3P7GR464.js | AI (source-diff): Bundled MCP server code; standard bundler preamble, no fetched-binary exec. | ai | |
| source-diff | obfuscated-file:dist/dist-3P7GR464.js | AI (source-diff): tsup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-EUFTPI3I.js | AI (source-diff): Bundled MCP server entry, normal Node core imports. | ai | |
| source-diff | obfuscated-file:dist/dist-EUFTPI3I.js | AI (source-diff): tsup-minified MCP bundle output. | ai | |
| source-diff | obfuscated-file:dist/dist-NS5Q6LD2.js | AI (source-diff): Minified tsup bundle of MCP server, not true obfuscation (no _0x/eval-atob). | ai | |
| source-diff | net-exec-file:dist/dist-NS5Q6LD2.js | AI (source-diff): Bundled MCP server using standard Node http/crypto/fs modules. | ai | |
| source-diff | net-exec-file:dist/chunk-MISDVBTN.js | AI (source-diff): Bundled Sui SDK code; network+exec is expected functionality, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/dist-W6VLD5J7.js | AI (source-diff): tsup bundle output, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-W6VLD5J7.js | AI (source-diff): Bundled MCP integration code; standard node http/https module usage. | ai | |
| source-diff | net-exec-file:dist/dist-GYLRF72F.js | AI (source-diff): Bundled MCP server code using standard node modules. | ai | |
| source-diff | obfuscated-file:dist/dist-GYLRF72F.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-LJKS6IJU.js | AI (source-diff): tsup minified bundle, no true obfuscation signature present. | ai | |
| source-diff | net-exec-file:dist/chunk-4YV63VD3.js | AI (source-diff): Bundled Sui SDK chunk; network+require patterns are normal RPC client code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-LJKS6IJU.js | AI (source-diff): Bundled MCP server output; matches package's stated CLI/MCP function. | ai | |
| source-diff | obfuscated-file:dist/dist-WY7S7WHQ.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-WY7S7WHQ.js | AI (source-diff): Bundled MCP+SDK entrypoint; expected for CLI wallet tool. | ai | |
| source-diff | obfuscated-file:dist/dist-JJ5SGNRQ.js | AI (source-diff): Bundled MCP package output, standard tsup/esbuild banner. | ai | |
| source-diff | net-exec-file:dist/dist-JJ5SGNRQ.js | AI (source-diff): Bundled MCP output; network+crypto imports are legitimate deps. | ai | |
| source-diff | net-exec-file:dist/dist-RE42ANOX.js | AI (source-diff): Bundled @t2000/mcp output; standard node builtins, not dropper code. | ai | |
| source-diff | obfuscated-file:dist/dist-RE42ANOX.js | AI (source-diff): tsup/esbuild bundler output (long lines), not true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-73ESA7QZ.js | AI (source-diff): Bundled ajv/sui vendor code inside tsup output. | ai | |
| source-diff | net-exec-file:dist/chunk-ZNF5QSAT.js | AI (source-diff): Bundled @mysten/sui SDK code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-7XXDSTKS.js | AI (source-diff): tsup-bundled CLI entry including MCP server; require-shim is standard ESM/CJS interop boilerplate. | ai | |
| source-diff | obfuscated-file:dist/dist-7XXDSTKS.js | AI (source-diff): Minified tsup bundle, not obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/dist-B2SOIJR7.js | AI (source-diff): Bundler-generated minified file, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-B2SOIJR7.js | AI (source-diff): Bundled MCP/CLI entry with SDK deps; no malicious payload in sample. | ai | |
| source-diff | net-exec-file:dist/dist-ZHHT2ROZ.js | AI (source-diff): tsup-bundled dependency chunk, standard build output. | ai | |
| source-diff | net-exec-file:dist/chunk-DNBWOMKV.js | AI (source-diff): tsup-bundled dependency code (ajv/sui SDK), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-7QRKMV5A.js | AI (source-diff): Bundled MCP server code with standard node http/https imports. | ai | |
| source-diff | obfuscated-file:dist/dist-7QRKMV5A.js | AI (source-diff): tsup-bundled MCP/CLI code; long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-72NNY4EV.js | AI (source-diff): Bundled ajv/dependency code in tsup output, not a loader/dropper; matches CLI's stated function. | ai | |
| source-diff | net-exec-file:dist/dist-5FWULUJE.js | AI (source-diff): Bundled MCP server code (tsup output), not dropper logic. | ai | |
| source-diff | obfuscated-file:dist/dist-5FWULUJE.js | AI (source-diff): Minified tsup bundle, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-B43ZP5VT.js | AI (source-diff): Bundled build output (tsup/esbuild) containing ajv codegen, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-4WZTT2K6.js | AI (source-diff): tsup bundle output, no obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-4WZTT2K6.js | AI (source-diff): tsup-bundled MCP entrypoint; matches stated CLI/MCP integration functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-FGD5U3UK.js | AI (source-diff): tsup/esbuild bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-FGD5U3UK.js | AI (source-diff): tsup-bundled MCP/CLI entry; dynamic require polyfill is standard esbuild/tsup output. | ai | |
| source-diff | obfuscated-file:dist/dist-Z4REI6RI.js | AI (source-diff): tsup bundler output, not true obfuscation; matches CLI's MCP/wallet functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-YIDWTGXL.js | AI (source-diff): Bundled SDK code (Sui/MCP), network+crypto imports match stated wallet/RPC function. | ai | |
| source-diff | net-exec-file:dist/dist-Z4REI6RI.js | AI (source-diff): Same bundled MCP integration file, network use aligns with package purpose. | ai | |
| source-diff | net-exec-file:dist/chunk-KNOTIQIW.js | AI (source-diff): Bundled @mysten/sui crypto lib code, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-DFNVSDCZ.js | AI (source-diff): Bundled ajv/commonjs shim, standard tsup output. | ai | |
| source-diff | obfuscated-file:dist/esm-4AK2OVKH.js | AI (source-diff): Long lines are bundled poseidon-lite/crypto deps, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-YAOR56AO.js | AI (source-diff): Bundled MCP server code; http/crypto imports are core to stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-YAOR56AO.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation (no _0x/eval-atob patterns). | ai | |
| source-diff | net-exec-file:dist/dist-WS6MYX6E.js | AI (source-diff): Bundled MCP/wallet server code; network+crypto is expected for this CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-WS6MYX6E.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-ADRZ3DGP.js | AI (source-diff): tsup-bundled MCP/CLI entry, uses standard node builtins. | ai | |
| source-diff | obfuscated-file:dist/dist-ADRZ3DGP.js | AI (source-diff): Long lines are minified bundler output, no _0x/eval obfuscation present. | ai | |
| source-diff | net-exec-file:dist/chunk-VZAS6UYO.js | AI (source-diff): Bundled Sui SDK code, standard bundler output. | ai | |
| source-diff | net-exec-file:dist/dist-BCZL4RIK.js | AI (source-diff): Bundled ajv/commonjs shim code, not a dropper; standard tsup build output. | ai | |
| source-diff | net-exec-file:dist/dist-TTOWKQCE.js | AI (source-diff): Bundled ajv library code (tsup output), not a dropper/loader; net+eval pattern is ajv internals. | ai | |
| source-diff | obfuscated-file:dist/dist-IKHAYUNB.js | AI (source-diff): Minified bundler output from tsup build, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-IKHAYUNB.js | AI (source-diff): tsup bundle of MCP server; network/crypto use matches stated purpose. | ai | |
| source-diff | net-exec-file:dist/dist-LWNHQ556.js | AI (source-diff): Bundled MCP server module; standard node crypto/http usage, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-LWNHQ556.js | AI (source-diff): tsup/esbuild bundler banner, long minified lines — not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-OXY5OEJY.js | AI (source-diff): Same bundled MCP output; network/crypto usage matches package's wallet function. | ai | |
| source-diff | obfuscated-file:dist/dist-OXY5OEJY.js | AI (source-diff): Minified bundle of MCP server code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-V7LLENR6.js | AI (source-diff): tsup bundle of CLI/MCP entrypoint, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-V7LLENR6.js | AI (source-diff): Minified bundler output (long lines), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-XF4YOVL6.js | AI (source-diff): Bundled build output (long lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-XF4YOVL6.js | AI (source-diff): tsup-bundled MCP/CLI entry, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/dist-VCKOEVZF.js | AI (source-diff): tsup-bundled MCP/CLI entry using Node crypto/http for wallet ops, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/dist-VCKOEVZF.js | AI (source-diff): tsup bundler output, not obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/dist-4BEH22UU.js | AI (source-diff): tsup bundler banner/minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-4BEH22UU.js | AI (source-diff): tsup-bundled CLI/MCP entry using node core http/crypto, not exfil. | ai | |
| source-diff | net-exec-file:dist/chunk-JKL4VB6Z.js | AI (source-diff): Bundled Sui SDK code (network client + crypto), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-HSP7IKBK.js | AI (source-diff): Bundled MCP module; standard node builtins, not a fetched/executed payload. | ai | |
| source-diff | obfuscated-file:dist/dist-HSP7IKBK.js | AI (source-diff): tsup/esbuild bundled output with long minified lines, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-HHTSJ65N.js | AI (source-diff): tsup-bundled MCP/CLI code with long lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-HHTSJ65N.js | AI (source-diff): Bundled MCP server code using standard node builtins, not exfil/dropper behavior. | ai | |
| source-diff | net-exec-file:dist/dist-D7DSJO25.js | AI (source-diff): Bundled ajv codegen + t2000 SDK code, standard tsup output. | ai | |
| source-diff | net-exec-file:dist/chunk-MHJ6L6JJ.js | AI (source-diff): Bundled @mysten/sui transaction/bcs code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-EGIY4JBI.js | AI (source-diff): Bundled tsup output importing SDK modules, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-FREI2C5T.js | AI (source-diff): Long lines are minification from tsup/esbuild bundling, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-FREI2C5T.js | AI (source-diff): Bundled MCP SDK code with standard Node builtins, not malicious. | ai | |
| source-diff | net-exec-file:dist/dist-S3TI3ZJO.js | AI (source-diff): Bundled MCP server entrypoint, network use matches CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-S3TI3ZJO.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-TQO3CQHJ.js | AI (source-diff): tsup-bundled MCP server entry, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/dist-TQO3CQHJ.js | AI (source-diff): tsup bundle artifact, matches package build process. | ai | |
| source-diff | obfuscated-file:dist/dist-FD2EWRJG.js | AI (source-diff): tsup bundle output; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-FD2EWRJG.js | AI (source-diff): tsup-bundled MCP/CLI entry; http/crypto imports match stated wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-BHM4NALL.js | AI (source-diff): tsup bundler preamble/boilerplate, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-BHM4NALL.js | AI (source-diff): Main bundled CLI/MCP entry, tsup build output. | ai | |
| source-diff | net-exec-file:dist/dist-PGQB2FNL.js | AI (source-diff): Sui RPC/crypto client network+require is core CLI function, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/dist-PGQB2FNL.js | AI (source-diff): tsup-bundled workspace build output, long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-QJMWLHVB.js | AI (source-diff): tsup-bundled MCP index with long lines; minification not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-QJMWLHVB.js | AI (source-diff): Same bundled MCP file; builtins usage, no hostile destination found. | ai | |
| source-diff | obfuscated-file:dist/dist-BX75AB5B.js | AI (source-diff): Bundled build artifact; readable variable names, no obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-BX75AB5B.js | AI (source-diff): Main bundled CLI entry incl. MCP server; network/crypto imports match stated function. | ai | |
| source-diff | net-exec-file:dist/chunk-RH2GPQCO.js | AI (source-diff): Bundled Sui SDK code with legitimate network/crypto use, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-L754V6AR.js | AI (source-diff): Long lines are bundler minification artifact, no obfuscation signature present. | ai | |
| source-diff | net-exec-file:dist/dist-L754V6AR.js | AI (source-diff): tsup bundle of MCP+SDK entrypoint, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-LLNAGKYO.js | AI (source-diff): Same bundled MCP server file; network/crypto imports are stated functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-LLNAGKYO.js | AI (source-diff): tsup-bundled MCP server output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-HPNCDFEJ.js | AI (source-diff): Bundled MCP server entrypoint; network/crypto imports match stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-HPNCDFEJ.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-P7CVUSZI.js | AI (source-diff): Bundled Sui SDK chunk, same rationale. | ai | |
| source-diff | net-exec-file:dist/dist-7M62MFJX.js | AI (source-diff): tsup-bundled MCP/CLI entry; contains standard node builtins, not malicious. | ai | |
| source-diff | obfuscated-file:dist/dist-7M62MFJX.js | AI (source-diff): Minified tsup bundle, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-TZ3QMOXQ.js | AI (source-diff): tsup bundle banner/minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-TZ3QMOXQ.js | AI (source-diff): Main bundled CLI/MCP entry, tsup output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-2YPKQJOZ.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-2YPKQJOZ.js | AI (source-diff): Bundled CLI/MCP entrypoint using node crypto for wallet key mgmt, not exfil. | ai | |
| source-diff | obfuscated-file:dist/dist-Q3LMDXT2.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation; matches package.json deps. | ai | |
| source-diff | net-exec-file:dist/dist-Q3LMDXT2.js | AI (source-diff): Bundled MCP server code performing legitimate network/crypto ops for wallet CLI. | ai | |
| source-diff | net-exec-file:dist/chunk-LXS47BB5.js | AI (source-diff): Bundled Sui SDK client code; network calls are RPC to blockchain, not exfil. | ai | |
| source-diff | net-exec-file:dist/dist-OUAHGUUD.js | AI (source-diff): Bundled http/https/crypto usage from MCP/SDK client code, no hostile target found. | ai | |
| source-diff | obfuscated-file:dist/dist-OUAHGUUD.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation; long minified lines only. | ai | |
| source-diff | net-exec-file:dist/chunk-Q52KM4VI.js | AI (source-diff): Sui SDK transaction/RPC code bundled in; net+exec pattern is incidental to normal wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-HQYY3REM.js | AI (source-diff): tsup-bundled MCP/CLI entry, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-HQYY3REM.js | AI (source-diff): Bundled CLI/MCP entrypoint with expected network+crypto usage. | ai | |
| source-diff | net-exec-file:dist/dist-4VDCOYPA.js | AI (source-diff): Main bundled entry importing MCP/SDK code; matches stated CLI function. | ai | |
| source-diff | obfuscated-file:dist/dist-4VDCOYPA.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UFYDHMQG.js | AI (source-diff): tsup-bundled MCP/CLI entrypoint, expected network+crypto imports. | ai | |
| source-diff | obfuscated-file:dist/dist-UFYDHMQG.js | AI (source-diff): tsup bundler preamble/minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-A7KVZIUL.js | AI (source-diff): Minified bundled build output (tsup), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-A7KVZIUL.js | AI (source-diff): Bundled MCP/CLI entry containing crypto+http imports, expected for this tool. | ai | |
| source-diff | net-exec-file:dist/chunk-G2DXW5RK.js | AI (source-diff): Bundled Sui SDK chunk; network+require inherent to blockchain CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-R6F53QGO.js | AI (source-diff): tsup/esbuild bundle output (long lines from minification), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-R6F53QGO.js | AI (source-diff): Bundled Sui RPC client; network+require are core CLI function, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/dist-K4ONVV5A.js | AI (source-diff): tsup bundle output, standard minification. | ai | |
| source-diff | net-exec-file:dist/dist-K4ONVV5A.js | AI (source-diff): Bundled MCP/CLI entry combining SDK deps, expected for this tool. | ai | |
| source-diff | net-exec-file:dist/chunk-IR2QGWUU.js | AI (source-diff): Bundled Sui SDK network client code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-Z74HUTKM.js | AI (source-diff): Bundled Sui SDK network client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-C2DPFH2K.js | AI (source-diff): Bundled/minified tsup output, not true obfuscation (no _0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/chunk-PUT73QY7.js | AI (source-diff): Bundled Sui SDK transaction module, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-C2DPFH2K.js | AI (source-diff): Bundled SDK/CLI with normal http(s) usage for RPC; no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-NVVRO5EM.js | AI (source-diff): Bundled @mysten/sui SDK code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-I2SVTLMJ.js | AI (source-diff): Bundled ajv/zod validation code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-ZB7UNB3B.js | AI (source-diff): tsup-bundled CLI/MCP entry, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-GGXOFR5Y.js | AI (source-diff): Bundled Sui SDK chunk with legitimate network/crypto use, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-ZB7UNB3B.js | AI (source-diff): Minified bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-DFRBOZ6E.js | AI (source-diff): Bundled @mysten/sui transaction/client code, not a dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by bundling @mysten/sui SDK into dist. | ai | |
| source-diff | net-exec-file:dist/dist-UUEYYCY7.js | AI (source-diff): Bundled ajv/commonjs shim code via tsup, not a loader. | ai | |
| source-diff | obfuscated-file:dist/esm-H7KTI5UT.js | AI (source-diff): Bundled poseidon-lite/sui crypto utils, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/dist-O7TEQEPW.js | AI (source-diff): Minified bundler output, no true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-O7TEQEPW.js | AI (source-diff): tsup-bundled MCP/CLI entrypoint; imports are standard Node builtins. | ai | |
| source-diff | obfuscated-file:dist/dist-SX2PWORA.js | AI (source-diff): Bundled build artifact with bundler helper shims, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-SX2PWORA.js | AI (source-diff): Main CLI bundle including MCP server; crypto/network use matches stated wallet functionality. | ai | |
| source-diff | net-exec-file:dist/dist-NXFA54RO.js | AI (source-diff): Bundled ajv codegen + hono server chunk via tsup, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/dist-UT5P3QKA.js | AI (source-diff): Main CLI bundle via tsup; network/crypto imports are wallet functionality. | ai | |
| source-diff | obfuscated-file:dist/dist-UT5P3QKA.js | AI (source-diff): tsup bundle output, long lines but readable headers/source. | ai | |
| source-diff | net-exec-file:dist/dist-PHUQOID4.js | AI (source-diff): tsup-bundled MCP entrypoint; long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-PHUQOID4.js | AI (source-diff): tsup bundle output, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/dist-76K7ACSI.js | AI (source-diff): tsup/esbuild bundled output, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/dist-76K7ACSI.js | AI (source-diff): tsup bundle of MCP/CLI entry, matches stated wallet/MCP functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-2TOYZOH3.js | AI (source-diff): Bundled Sui SDK RPC client code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-EJKUXGU5.js | AI (source-diff): tsup bundle of CLI/MCP entrypoint, standard bundler boilerplate. | ai | |
| source-diff | obfuscated-file:dist/dist-EJKUXGU5.js | AI (source-diff): Minified bundled output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-6ELHCFGI.js | AI (source-diff): Bundled ajv/codegen library output flagged by heuristic; not actual dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-J7ICN5BN.js | AI (source-diff): tsup bundle banner, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-ZNZ4MOY2.js | AI (source-diff): Bundled Sui RPC client code, matches wallet CLI's stated function. | ai | |
| source-diff | net-exec-file:dist/dist-J7ICN5BN.js | AI (source-diff): tsup-bundled MCP server entrypoint, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-UDLQ4IJN.js | AI (source-diff): tsup bundle output, long lines are build artifact not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UDLQ4IJN.js | AI (source-diff): Main bundled entrypoint (tsup output), no dropper behavior found. | ai | |
| source-diff | net-exec-file:dist/chunk-YSV3YXTK.js | AI (source-diff): Bundled Sui RPC client code; network calls are the wallet's core function. | ai | |
| source-diff | obfuscated-file:dist/dist-CIFLOG63.js | AI (source-diff): tsup bundle of MCP server, build artifact not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-CIFLOG63.js | AI (source-diff): Bundled MCP server entrypoint using crypto/http, part of stated agent-wallet functionality. | ai | |
| source-diff | net-exec-file:dist/dist-TY5WWYFJ.js | AI (source-diff): Main bundled entrypoint via tsup; standard build output. | ai | |
| source-diff | obfuscated-file:dist/dist-TY5WWYFJ.js | AI (source-diff): tsup bundle, long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-QT4VURPN.js | AI (source-diff): tsup/esbuild bundle of MCP+SDK, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/dist-QT4VURPN.js | AI (source-diff): Bundled MCP server code with legit http/crypto usage. | ai | |
| source-diff | obfuscated-file:dist/dist-NXNOD5S6.js | AI (source-diff): Bundled MCP/CLI entrypoint; standard build artifact. | ai | |
| source-diff | net-exec-file:dist/dist-NXNOD5S6.js | AI (source-diff): Bundled CLI/MCP code using http/crypto normally, matches wallet CLI purpose. | ai | |
| source-diff | net-exec-file:dist/chunk-UNDAINCC.js | AI (source-diff): Bundled Sui SDK code; network+crypto imports are library functionality, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/client-QWWT5U25.js | AI (source-diff): tsup/esbuild bundle output, long lines from minification not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-6CNQQWXH.js | AI (source-diff): tsup bundle entrypoint with standard require shim, not malicious loader. | ai | |
| source-diff | obfuscated-file:dist/dist-6CNQQWXH.js | AI (source-diff): Bundled build artifact, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/dist-OJ3GTZ7L.js | AI (source-diff): tsup bundle including MCP server, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-OJ3GTZ7L.js | AI (source-diff): Bundled MCP/CLI code with legit crypto/net usage for wallet tool. | ai | |
| source-diff | net-exec-file:dist/dist-CPQKUT3C.js | AI (source-diff): Bundled MCP server entry using standard node http/crypto modules. | ai | |
| source-diff | obfuscated-file:dist/dist-CPQKUT3C.js | AI (source-diff): tsup/esbuild bundle output, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-WX3IBPYN.js | AI (source-diff): Bundled MCP server entry using node http/crypto modules, expected for stated function. | ai | |
| source-diff | obfuscated-file:dist/dist-WX3IBPYN.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KQITQOJI.js | AI (source-diff): Bundled MCP server + wallet crypto for local key handling. | ai | |
| source-diff | net-exec-file:dist/chunk-K6R5CJFK.js | AI (source-diff): Bundled Sui SDK client code, legitimate RPC calls. | ai | |
| source-diff | obfuscated-file:dist/dist-KQITQOJI.js | AI (source-diff): tsup/esbuild bundle output, long lines not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-IFQ2TJDI.js | AI (source-diff): tsup bundle of CLI entry incl. MCP server; standard node builtins. | ai | |
| source-diff | net-exec-file:dist/chunk-Y2HI3L2W.js | AI (source-diff): Bundled Sui SDK networking code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-IFQ2TJDI.js | AI (source-diff): Minified bundler output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-UVKQOQSP.js | AI (source-diff): tsup-bundled MCP server output, long lines from minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-UVKQOQSP.js | AI (source-diff): Bundled MCP server code; http/https/crypto imports match stated MCP integration feature. | ai | |
| source-diff | net-exec-file:dist/dist-BGQK2CN5.js | AI (source-diff): Bundled ajv codegen dependency, not a dropper; standard build output. | ai | |
| source-diff | net-exec-file:dist/dist-V2C7NCAD.js | AI (source-diff): Bundled ajv codegen + hono server code, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-PJEEL7WQ.js | AI (source-diff): Bundled build output from tsup, not obfuscation; contains readable vendored library code. | ai | |
| source-diff | net-exec-file:dist/dist-5TKR5HBZ.js | AI (source-diff): Bundled MCP SDK with standard node http/https imports, not exfil. | ai | |
| source-diff | obfuscated-file:dist/dist-5TKR5HBZ.js | AI (source-diff): tsup/esbuild bundle output, long lines from minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-MPQLFHSY.js | AI (source-diff): tsup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-MPQLFHSY.js | AI (source-diff): Bundled MCP integration code, legitimate imports. | ai | |
| source-diff | obfuscated-file:dist/dist-JDPHHZMS.js | AI (source-diff): tsup bundle output (long lines from bundling), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-JDPHHZMS.js | AI (source-diff): Bundled MCP server code with standard Node built-ins, not dropper malware. | ai | |
| source-diff | net-exec-file:dist/dist-GQYVQGH4.js | AI (source-diff): Bundled MCP/CLI entry with crypto+http imports, consistent with tool purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-GQYVQGH4.js | AI (source-diff): tsup bundler output (long lines), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-AY4QEDAC.js | AI (source-diff): Bundled ajv/sui SDK code shown in sample; standard tsup output. | ai | |
| source-diff | net-exec-file:dist/chunk-FSE25UF3.js | AI (source-diff): Bundled @mysten/sui SDK code, not injected loader logic. | ai | |
| source-diff | net-exec-file:dist/chunk-33M73WY4.js | AI (source-diff): Bundled Sui SDK/MCP code; network+crypto imports are standard, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-LYBZRU4W.js | AI (source-diff): Bundled build output (tsup), not true obfuscation; no malicious behavior present. | ai | |
| source-diff | net-exec-file:dist/dist-LYBZRU4W.js | AI (source-diff): tsup-bundled CLI/MCP entrypoint; long lines are bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-HZYKWFI3.js | AI (source-diff): Bundled Sui SDK/MCP code; network+crypto imports are standard, not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-HDTGCZUD.js | AI (source-diff): Bundled MCP+SDK entrypoint; standard node builtins imports, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dist-HDTGCZUD.js | AI (source-diff): tsup bundle output, same rationale. | ai | |
| source-diff | obfuscated-file:dist/dist-KT7X223A.js | AI (source-diff): Bundled build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KT7X223A.js | AI (source-diff): Main bundled entry including MCP server, expected network/exec use. | ai | |
| provenance | missing-githead | AI (provenance): Single-version gitHead gap on an otherwise consistent, high-volume active publisher. | ai | |
| source-diff | net-exec-file:dist/dist-5OPQU5C7.js | AI (source-diff): Bundled ajv/tsup codegen output, not a loader; net+eval pattern is from legitimate schema-compiler library. | ai | |
| source-diff | obfuscated-file:dist/client-SYS6Z5RX.js | AI (source-diff): Minified bundler output (viem), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-CSEWI4RS.js | AI (source-diff): Bundled ajv/commonjs shim code, standard tsup output. | ai | |
| source-diff | obfuscated-file:dist/esm-IQVNJILX.js | AI (source-diff): Bundled poseidon-lite/sui-types code, long lines from bundler not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-4FTMWFBO.js | AI (source-diff): Bundled Sui SDK code, not a dropper; no fetched-binary or exec-of-remote-code pattern. | ai | |
| source-diff | net-exec-file:dist/chunk-R7KXQRHQ.js | AI (source-diff): Bundled Sui SDK client code, not a loader — network+crypto expected for a wallet CLI. | ai | |
| source-diff | obfuscated-file:dist/dist-EUGE6UAA.js | AI (source-diff): tsup bundle output, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-EUGE6UAA.js | AI (source-diff): Bundled MCP server entrypoint; matches package's stated MCP integration feature. | ai | |
| source-diff | net-exec-file:dist/dist-YMS4HBBO.js | AI (source-diff): Main bundled entry incl. MCP server; matches package purpose. | ai | |
| source-diff | obfuscated-file:dist/dist-YMS4HBBO.js | AI (source-diff): tsup bundle output, long lines from minification not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-3DGYEM62.js | AI (source-diff): Bundled Sui SDK chunk; network+crypto usage matches wallet RPC/keystore function. | ai | |
| source-diff | obfuscated-file:dist/dist-JU2KFF74.js | AI (source-diff): Minified bundler output (tsup/esbuild banner visible), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-JU2KFF74.js | AI (source-diff): tsup bundle of MCP server entrypoint; crypto/http imports match documented CLI features. | ai | |
| source-diff | obfuscated-file:dist/dist-HYKRYVZV.js | AI (source-diff): tsup/esbuild bundled output, standard __esm/__commonJS helpers. | ai | |
| source-diff | net-exec-file:dist/chunk-ACFFT3J4.js | AI (source-diff): Bundled Sui RPC client code, not a dropper; wallet CLI needs network calls. | ai | |
| source-diff | net-exec-file:dist/dist-HYKRYVZV.js | AI (source-diff): tsup bundle of MCP server entrypoint with node builtins, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client-M732TO32.js | AI (source-diff): Minified bundle output (long lines), not true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/dist-OSTBPTHG.js | AI (source-diff): Bundled ajv/zod code via tsup, matches stated CLI function. | ai | |
| source-diff | net-exec-file:dist/chunk-CDQ2RJBX.js | AI (source-diff): Bundled Sui SDK code (tsup output), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-KMGEM6TT.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-KMGEM6TT.js | AI (source-diff): Bundled MCP/CLI code with standard node builtins, not malicious. | ai | |
| source-diff | net-exec-file:dist/dist-LGHHHTO2.js | AI (source-diff): Bundled Sui SDK + http/crypto usage matching stated wallet function; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-6ZRYQAOQ.js | AI (source-diff): Bundled Sui transaction SDK chunk; net+require is normal for this CLI's build output. | ai | |
| source-diff | obfuscated-file:dist/dist-LGHHHTO2.js | AI (source-diff): tsup/esbuild bundle output, not obfuscation; expected build artifact for this CLI. | ai | |
| source-diff | net-exec-file:dist/dist-V5TR4H22.js | AI (source-diff): Network+crypto code matches package's wallet/MCP functionality, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/dist-V5TR4H22.js | AI (source-diff): Bundled tsup/esbuild output, not true obfuscation; matches wallet CLI's stated crypto/network functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-H2UWSH2A.js | AI (source-diff): Bundled Sui SDK chunk (transaction/RPC code), not a dropper. | ai | |
| source-diff | net-exec-file:dist/dist-FAZJCWL5.js | AI (source-diff): Bundled ajv/schema validation code shipped with CLI, not a loader. | ai | |
| source-diff | net-exec-file:dist/chunk-DKZ2SS27.js | AI (source-diff): Bundled @mysten/sui SDK code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/client-IXUBQ3HM.js | AI (source-diff): Bundled viem library output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/dist-7EHHFP4Q.js | AI (source-diff): Bundled ajv/zod deps via tsup, not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-NXTB2IJH.js | AI (source-diff): Bundled Sui SDK chunk; network+require pattern is tsup scaffolding, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/dist-YXU2VTRS.js | AI (source-diff): Minified bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client-DOJP3IMM.js | AI (source-diff): Minified bundler output, not obfuscation (no _0x/eval-atob markers). | ai | |
| source-diff | net-exec-file:dist/dist-YXU2VTRS.js | AI (source-diff): Bundled MCP entrypoint; long import list matches stated CLI functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-TTDWK2PS.js | AI (source-diff): Bundled Sui SDK chunk; same tsup bundler pattern. | ai | |
| source-diff | obfuscated-file:dist/esm-SWUQQCXL.js | AI (source-diff): Bundled third-party crypto lib (poseidon-lite), minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunk-DHL3JOM5.js | AI (source-diff): Bundled Sui SDK network client, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-ZRPJE7U5.js | AI (source-diff): Bundled RPC/HTTP client code from @mysten/sui deps. | ai | |
| source-diff | net-exec-file:dist/dist-E7D67PXG.js | AI (source-diff): Bundled MCP server entrypoint using standard node http/crypto modules. | ai | |
| source-diff | obfuscated-file:dist/client-I5AZIDKN.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dist-E7D67PXG.js | AI (source-diff): tsup-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm-RF62MWQV.js | AI (source-diff): Bundled crypto libs (poseidon-lite) for Sui signing, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/dist-HTKRHJBX.js | AI (source-diff): tsup-bundled MCP entrypoint, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-HTKRHJBX.js | AI (source-diff): Bundled MCP server code using standard node http/https imports, consistent with stated MCP integration. | ai | |
| source-diff | net-exec-file:dist/chunk-SC3LZKLE.js | AI (source-diff): Bundled Sui SDK chunk (bignumber.js etc.), not a dropper; matches wallet functionality. | ai | |
| phantom-deps | phantom-dep:qrcode | AI (phantom-deps): qrcode is a well-known package; phantom-dep is a stable FP for this CLI package. | ai | |
| phantom-deps | phantom-dep:mppx | AI (phantom-deps): mppx appears to be a project-specific dependency used via config rather than direct import; phantom-dep is a stable FP here. | ai | |
| phantom-deps | phantom-dep:@mysten/sui | AI (phantom-deps): @mysten/sui is explicitly declared in dependencies; phantom-dep is a false positive for this package. | ai | |
| dependencies | unvetted-dep:@t2000/x402 | AI (dependencies): Sibling workspace package in the same monorepo; not an external unvetted dependency. | ai | |
| source-diff | net-exec-file:dist/chunk-2JUMTEBB.js | AI (source-diff): Bundled tsup output containing Sui SDK and standard library imports. The net+exec pattern is from legitimate blockchain SDK usage, not dropper malware. | ai | |
| source-diff | net-exec-file:dist/dist-UDCEDQVB.js | AI (source-diff): Bundled tsup output containing ajv and internal SDK imports. Standard bundler artifact, not malicious loader. | ai | |
| source-diff | net-exec-file:dist/chunk-FSSTF3LM.js | AI (source-diff): Bundled tsup output for a Sui DeFi CLI; network calls come from Sui SDK and HTTP client libs, dynamic require is standard ESM compat shim. No malicious payload. | ai | |
| source-diff | net-exec-file:dist/dist-55H37ULN.js | AI (source-diff): Same bundled tsup output pattern; imports ajv, Sui SDK, and internal chunks. No dropper/loader behavior evident in samples. | ai | |
| source-diff | net-exec-file:dist/dist-UOEUHDJW.js | AI (source-diff): Standard tsup/esbuild bundled output; contains ajv and other legitimate dependencies bundled via __commonJS shim. No malicious patterns visible. | ai | |
| source-diff | net-exec-file:dist/chunk-IEDON62D.js | AI (source-diff): Standard tsup/esbuild bundled output for a Sui DeFi CLI tool; imports are from @mysten/sui SDK. Network+exec pattern is a false positive for bundled CLI dependencies. | ai | |
| source-diff | obfuscated-file:dist/client-KQCHOXLV.js | AI (source-diff): Long lines are minified/bundled output from tsup, not intentional obfuscation. Content references standard viem error types consistent with DeFi CLI tooling. | ai | |
| source-diff | net-exec-file:dist/chunk-FM4762OE.js | AI (source-diff): Bundled CLI output for a Sui blockchain wallet; network calls and dynamic require shims are expected in tsup-built ESM artifacts. Not malicious. | ai | |
| source-diff | net-exec-file:dist/dist-ZTFOTMJO.js | AI (source-diff): Same as above — standard bundler output chunk with AJV and Sui SDK imports. Network + dynamic patterns are inherent to this CLI tool's legitimate function. | ai | |
| source-diff | net-exec-file:dist/chunk-BPTNEFB5.js | AI (source-diff): This is tsup-bundled output for a Sui blockchain CLI. Network calls are Sui RPC; dynamic require is a standard ESM shim. Source maps are present. Pattern is stable for this package. | ai | |
| provenance | no-provenance | AI (provenance): Package predates provenance adoption; no other risk signals. Low finding, acceptable for this package. | ai | |
| source-diff | net-exec-file:dist/dist-MJOXMRDV.js | AI (source-diff): Same tsup bundle pattern as chunk-BPTNEFB5.js. Imports ajv and internal chunks; no obfuscation. Consistent with legitimate DeFi CLI build output. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @t2000/cli is a Sui blockchain CLI tool with no relation to the joi validation library; the name similarity is purely coincidental and not impersonation. | ai |
Versions (showing 51 of 517)
| Version | Deps | Published |
|---|---|---|
| 5.28.0 | 1 / 15 | |
| 5.27.0 | 1 / 15 | |
| 5.26.0 | 1 / 15 | |
| 5.25.0 | 1 / 15 | |
| 5.24.3 | 1 / 15 | |
| 5.24.2 | 1 / 15 | |
| 5.24.1 | 1 / 15 | |
| 5.24.0 | 1 / 15 | |
| 5.23.0 | 1 / 15 | |
| 5.22.0 | 1 / 15 | |
| 5.21.0 | 1 / 15 | |
| 5.20.1 | 1 / 15 | |
| 5.20.0 | 1 / 15 | |
| 5.19.0 | 1 / 15 | |
| 5.18.0 | 1 / 15 | |
| 5.17.0 | 1 / 15 | |
| 5.16.0 | 1 / 15 | |
| 5.15.1 | 1 / 15 | |
| 5.15.0 | 1 / 15 | |
| 5.14.3 | 1 / 15 | |
| 5.14.2 | 1 / 15 | |
| 5.14.1 | 1 / 15 | |
| 5.14.0 | 1 / 15 | |
| 5.13.0 | 1 / 15 | |
| 5.12.0 | 1 / 15 | |
| 5.11.0 | 1 / 15 | |
| 5.10.0 | 1 / 15 | |
| 5.9.0 | 1 / 15 | |
| 5.8.0 | 1 / 15 | |
| 5.7.3 | 1 / 15 | |
| 5.7.2 | 1 / 15 | |
| 5.7.1 | 1 / 15 | |
| 5.7.0 | 1 / 15 | |
| 5.6.1 | 1 / 15 | |
| 5.6.0 | 1 / 15 | |
| 5.5.1 | 1 / 15 | |
| 5.5.0 | 1 / 15 | |
| 5.4.0 | 1 / 15 | |
| 5.3.0 | 1 / 15 | |
| 5.2.0 | 1 / 15 | |
| 5.1.0 | 1 / 15 | |
| 4.0.1 | 2 / 15 | |
| 4.0.0 | 2 / 15 | |
| 3.3.0 | 0 / 14 | |
| 3.2.0 | 0 / 14 | |
| 3.1.1 | 0 / 14 | |
| 3.1.0 | 0 / 14 | |
| 3.0.0 | 0 / 13 | |
| 2.20.3 | 0 / 13 | |
| 2.20.2 | 0 / 13 | |
| 2.20.1 | 0 / 13 |
v5.28.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.27.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.26.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.25.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.24.3
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.24.2
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.24.1
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.24.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.23.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.22.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.21.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.20.1
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.20.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.19.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.18.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.17.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.16.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.15.1
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.15.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.14.3
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.14.2
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.14.1
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.14.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.13.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.12.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.11.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.8.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.3
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.2
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.1
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.3
7 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.2
7 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.1
7 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.