← Home

@tangle-network/agent-runtime

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

vutuanlinh2k2drewstonetjemmmictin-tangle-tools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/coordination-o0TzS7Ms.d.ts AI (source-diff): Long-line .d.ts type bundle from tsup, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-7HH22XN4.js AI (source-diff): Bundled tsup chunk implementing the package's own sandbox/executor loop, not a dropper. ai
source-diff obfuscated-file:dist/coordination-DzXsfxre.d.ts AI (source-diff): Long-line .d.ts type declaration bundle, not obfuscated executable code. ai
source-diff net-exec-file:dist/chunk-7PSFJTJZ.js AI (source-diff): Bundled library code implementing sandbox/executor features, not a dropper. ai
source-diff net-exec-file:dist/chunk-SDR45ZQB.js AI (source-diff): Bundled executor/sandbox module, matches stated agent-runtime execution purpose. ai
source-diff obfuscated-file:dist/coordination-CdU8LyvB.d.ts AI (source-diff): Long-line TypeScript declaration file from build, not obfuscated executable code. ai
source-diff net-exec-file:dist/chunk-L4CACVIJ.js AI (source-diff): tsup-bundled re-export chunk, not a dropper; no actual net+exec payload shown. ai
source-diff obfuscated-file:dist/coordination-pOGZuYS7.d.ts AI (source-diff): Long-line .d.ts is generated type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-GKZ6DFDN.js AI (source-diff): Bundled tsup output re-exporting sandbox/executor code; no actual dropper/loader behavior in sample. ai
source-diff obfuscated-file:dist/coordination-EGoRbbsd.d.ts AI (source-diff): Long-line .d.ts type-export file from bundler, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-OO4EK3JB.js AI (source-diff): Bundled tsup chunk re-exporting internal modules; no actual network+exec malware pattern. ai
source-diff obfuscated-file:dist/delegates-htF7l_H6.d.ts AI (source-diff): Long-line .d.ts type declarations, not code obfuscation. ai
source-diff net-exec-file:dist/chunk-ZADWPBOE.js AI (source-diff): Bundled utility chunk (tsup output); no actual network+exec dropper behavior in sample. ai
source-diff net-exec-file:dist/chunk-I7WVPJBZ.js AI (source-diff): Bundled tsup chunk importing sibling chunks; no fetched-binary or exfil behavior in sample. ai
provenance regressed-provenance AI (provenance): Manual publish by known maintainer per publisher-changed-known-maintainer INFO finding. ai
source-diff net-exec-file:dist/chunk-6K5CI33W.js AI (source-diff): tsup-bundled chunk; sample shows plain module re-exports, not a dropper. ai
source-diff net-exec-file:dist/chunk-BVVRQ4YC.js AI (source-diff): Bundled sandbox/executor code matching package purpose, not a dropper. ai
source-diff obfuscated-file:dist/coordination-DxJ83oZA.d.ts AI (source-diff): Long type-declaration import line, not true obfuscation. ai
source-diff net-exec-file:dist/chunk-D336OZHK.js AI (source-diff): Bundled tsup chunk for sandbox/executor runtime; sample shows normal module re-exports, no dropper behavior. ai
source-diff obfuscated-file:dist/coordination-B3ZuApR_.d.ts AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-JYURIKPF.js AI (source-diff): Bundled build output of sandbox/executor runtime, not a dropper; matches package's stated function. ai
source-diff net-exec-file:dist/chunk-FQH33M5N.js AI (source-diff): tsup-bundled chunk with normal async/crypto helpers, not a dropper. ai
source-diff obfuscated-file:dist/coordination-DU0saWeg.d.ts AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-HPYWEFVY.js AI (source-diff): Bundled build output; sample shows normal runtime logic, no fetched/executed payload. ai
source-diff obfuscated-file:dist/coordination-Csxsy39a.d.ts AI (source-diff): Generated .d.ts type-declaration file with long import lines, not obfuscation. ai
source-diff net-exec-file:dist/chunk-YHS6I2IS.js AI (source-diff): tsup-bundled chunk of runtime code, no fetched binary or exfil destination. ai
source-diff net-exec-file:dist/chunk-VKVNDNG4.js AI (source-diff): Bundled tsup output for a sandbox-executor library; sample shows normal module re-exports, not a loader payload. ai
source-diff net-exec-file:dist/chunk-3TZOXS7B.js AI (source-diff): tsup bundle chunk containing runtime executor code, not a dropper; readable JS with normal imports. ai
source-diff net-exec-file:dist/chunk-SN3XBTTH.js AI (source-diff): Bundled orchestration code (tsup chunk), no dropper/loader behavior in sample. ai
source-diff net-exec-file:dist/chunk-3RAXZ6LB.js AI (source-diff): Bundled build chunk with normal imports; no fetch+exec of foreign payload. ai
source-diff net-exec-file:dist/chunk-QSO2TVDS.js AI (source-diff): Bundled agent-runtime orchestration code, not a network+exec dropper. ai
source-diff obfuscated-file:dist/coordination-DCmljYDf.d.ts AI (source-diff): Long-line TypeScript .d.ts import list, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-AG335EXG.js AI (source-diff): Bundled tsup chunk of runtime logic, not a network dropper. ai
source-diff obfuscated-file:dist/coordination-CZe4lTxy.d.ts AI (source-diff): Minified .d.ts with long import lines from bundler, not true obfuscation. ai
source-diff net-exec-file:dist/chunk-CEW5BMGN.js AI (source-diff): Bundled tsup output, not a dropper; sample shows normal runtime module code. ai
source-diff obfuscated-file:dist/coordination-CFVF0OzX.d.ts AI (source-diff): Long-line minified .d.ts type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-PHKNOAOU.js AI (source-diff): Bundled runtime code (tsup chunk), not a dropper; sample shows normal module imports. ai
source-diff net-exec-file:dist/chunk-45D64J7B.js AI (source-diff): Bundled runtime chunk (tsup output), sample shows benign sandbox/journal utility code, not a dropper. ai
source-diff net-exec-file:dist/chunk-CM2IK7VS.js AI (source-diff): Sample shows normal runtime utility code, no dropper behavior. ai
source-diff obfuscated-file:dist/delegates-CWMv_rKL.d.ts AI (source-diff): Long-line .d.ts is verbose type declarations/comments, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-VCOT7XEQ.js AI (source-diff): Bundled tsup chunk; sample shows benign utility/crypto code, not a dropper. ai
source-diff source-size-tripled AI (source-diff): Consistent with legit build growth, no obfuscation/exfil found. ai
provenance missing-githead AI (provenance): Publish env variance for trusted maintainer, no behavioral signal. ai
source-diff obfuscated-file:dist/coordination-rRj5hjJK.d.ts AI (source-diff): Long-line .d.ts type declarations, not obfuscated JS. ai
dependencies unvetted-dep:@tangle-network/agent-profile-materialize AI (dependencies): First-party @tangle-network sibling package, part of same monorepo ecosystem. ai
source-diff net-exec-file:dist/chunk-AD7JW4QG.js AI (source-diff): Bundled tsup chunk re-exporting internal executor/sandbox modules, not a dropper. ai
source-diff net-exec-file:dist/chunk-YFOPWG74.js AI (source-diff): Bundled build chunk implementing documented sandbox harness spawning, not a dropper. ai
source-diff net-exec-file:dist/chunk-QDVLTRCP.js AI (source-diff): Bundled sandbox/executor code, not a dropper; consistent with package's stated function. ai
source-diff net-exec-file:dist/chunk-22HPUH77.js AI (source-diff): Bundled tsup output of package's own sandbox/executor runtime, not injected code. ai
source-diff obfuscated-file:dist/kb-gate-CKfykcYQ.d.ts AI (source-diff): Long-line .d.ts from bundled type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-K6WP7PYW.js AI (source-diff): Bundled tsup chunk containing normal runtime utility/crypto code, not a dropper. ai
source-diff net-exec-file:dist/chunk-VKUHUFX7.js AI (source-diff): Bundled tsup chunk with normal runtime logic, not a dropper; no fetched binary or exfil target. ai
source-diff net-exec-file:dist/chunk-MDFZSPHA.js AI (source-diff): Bundled build chunk with legit runtime code, not a loader/dropper. ai
source-diff obfuscated-file:dist/delegates-C94qchkz.d.ts AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-RLDUT4JL.js AI (source-diff): Bundled build chunk with normal async/crypto usage, not a dropper. ai
source-diff net-exec-file:dist/chunk-UJW6EVNY.js AI (source-diff): Bundled agent-runtime code (sandbox executor/loop primitives), not a dropper; matches package's own purpose. ai
source-diff obfuscated-file:dist/coordination-BoEPhGas.d.ts AI (source-diff): Minified .d.ts type file, not obfuscated malicious code. ai
source-diff net-exec-file:dist/chunk-75V2XXYJ.js AI (source-diff): Bundled tsup chunk of legit executor/sandbox code, not a dropper. ai
source-diff net-exec-file:dist/chunk-MT4XM3G6.js AI (source-diff): Bundled build chunk from tsup; sample shows ordinary async utility code, not a loader. ai
source-diff net-exec-file:dist/chunk-AHZ3YBL6.js AI (source-diff): Bundled tsup chunk with normal runtime imports, not a dropper. ai
source-diff obfuscated-file:dist/coordination-BFVtgRax.d.ts AI (source-diff): Minified .d.ts type declarations from build tool, not obfuscation. ai
source-diff net-exec-file:dist/chunk-NLRA6434.js AI (source-diff): Bundled runtime code implementing agent sandbox execution, not dropper/loader behavior. ai
source-diff obfuscated-file:dist/coordination-c_7Olmtq.d.ts AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. ai
source-diff net-exec-file:dist/chunk-DLAEEF26.js AI (source-diff): Bundled tsup chunk with legible named exports for sandbox/agent runtime, not a dropper. ai
source-diff obfuscated-file:dist/coordination-BI9tpcmF.d.ts AI (source-diff): Long-line .d.ts is generated type bundling, not obfuscation. ai
source-diff net-exec-file:dist/chunk-D6GIWPKD.js AI (source-diff): Bundled tsup chunk with normal imports/network client code, not a dropper. ai
source-diff obfuscated-file:dist/coordination-09JTQnlF.d.ts AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-N2JJDGLJ.js AI (source-diff): Bundled tsup chunk with sandbox/executor abstractions matching package's stated function, not a loader. ai
source-diff obfuscated-file:dist/coordination-DEVknvQo.d.ts AI (source-diff): Generated .d.ts with long import lines, not obfuscation. ai
source-diff net-exec-file:dist/chunk-SA5GCF2X.js AI (source-diff): Bundled build chunk of legitimate runtime code, not a dropper. ai
source-diff large-new-source-files AI (source-diff): Expected growth from tsup bundling/type generation across many versions. ai
source-diff obfuscated-file:dist/kb-gate-CHAyt4aI.d.ts AI (source-diff): Long lines are bundled .d.ts type re-exports, not obfuscated code. ai
source-diff net-exec-file:dist/chunk-2OU7ZQPD.js AI (source-diff): Bundled TS helper code (crypto/util), no fetched-binary or exfil behavior. ai
source-diff obfuscated-file:dist/coordination-CuDLO8wj.d.ts AI (source-diff): Long-line .d.ts type declarations from tsup/rollup dts bundling, not obfuscation. ai
source-diff net-exec-file:dist/chunk-PIPPLSOF.js AI (source-diff): Bundled ESM chunk re-exporting library functions, not a dropper/loader. ai
source-diff net-exec-file:dist/chunk-4IBAMGBE.js AI (source-diff): Bundled executor/sandbox runtime code, not a dropper; no fetched-binary or exfil pattern in sample. ai
source-diff obfuscated-file:dist/coordination-DxHduZg7.d.ts AI (source-diff): Minified .d.ts type declarations from tsup bundling, not true obfuscation. ai
source-diff obfuscated-file:dist/delegates-DqAgo32T.d.ts AI (source-diff): Long-line .d.ts type declaration file from bundler output, not obfuscation. ai
source-diff net-exec-file:dist/chunk-QXWGSDAQ.js AI (source-diff): Bundled tsup output for an agent-runtime package; sample shows normal utility code, no dropper behavior. ai
source-diff net-exec-file:dist/chunk-JTH2FPCK.js AI (source-diff): Bundled agent-runtime logic; sample shows no malicious network/exec behavior, just normal async utilities. ai
source-diff obfuscated-file:dist/delegates-BPLIl8EC.d.ts AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup bundler output, not obfuscation. ai
source-diff obfuscated-file:dist/delegates-CLFNAKyi.d.ts AI (source-diff): TypeScript declaration file with long JSDoc/type lines; not obfuscation. ai
source-diff net-exec-file:dist/chunk-J6DAU44N.js AI (source-diff): Bundled dist chunk with standard agent-runtime logic; no fetched binaries or exfil behavior. ai
source-diff net-exec-file:dist/chunk-5ISW5JUF.js AI (source-diff): Bundled tsup/esbuild output with first-party imports; no dropper behavior in sample. ai
source-diff obfuscated-file:dist/delegates-CsXJPZDH.d.ts AI (source-diff): TypeScript declaration file; long lines are concatenated type signatures, not obfuscation. ai
source-diff net-exec-file:dist/chunk-IW2LMLK6.js AI (source-diff): Bundled tsup/esbuild output with readable TS source; network+exec pattern is the agent runtime's core function, not a dropper. ai
source-diff net-exec-file:dist/chunk-PXUTIMGJ.js AI (source-diff): Sample shows normal bundled TS runtime utilities (crypto.randomUUID, sleep, abort helpers); no malicious payload. ai
provenance no-provenance AI (provenance): Established tangle-network package; lack of Sigstore provenance is a process gap, not a security risk here. ai
source-diff obfuscated-file:dist/delegates-D9o5_VFj.d.ts AI (source-diff): TypeScript declaration file with long re-export lines; not obfuscated code. ai
source-diff net-exec-file:dist/chunk-4H2FML7G.js AI (source-diff): Sample shows legitimate agent-runtime bundled code (crypto, sandbox utilities); no dropper/loader patterns. ai
provenance publisher-changed AI (provenance): Change from drewstone to GitHub Actions reflects CI/CD automation, consistent with SLSA provenance attestation present on this package. ai
source-diff obfuscated-file:dist/runtime.d.ts AI (source-diff): TypeScript declaration file with long re-export lines; not obfuscated code. ai

Versions (showing 100 of 138)

Version Deps Published
0.94.9 3 / 13
0.94.8 3 / 13
0.94.7 3 / 13
0.94.6 3 / 13
0.94.5 2 / 12
0.94.4 2 / 12
0.94.3 2 / 12
0.94.2 2 / 12
0.94.1 2 / 12
0.94.0 2 / 12
0.93.2 2 / 12
0.93.1 2 / 12
0.93.0 2 / 12
0.92.1 2 / 12
0.92.0 2 / 12
0.91.0 2 / 12
0.90.1 1 / 12
0.90.0 1 / 12
0.89.0 0 / 12
0.88.0 0 / 12
0.87.0 0 / 12
0.86.0 0 / 12
0.85.0 0 / 12
0.84.0 0 / 12
0.83.0 0 / 12
0.82.0 0 / 12
0.81.1 0 / 12
0.81.0 0 / 12
0.80.1 0 / 12
0.80.0 0 / 12
0.79.4 0 / 12
0.79.3 0 / 12
0.79.2 0 / 12
0.79.1 0 / 12
0.79.0 0 / 12
0.78.0 0 / 12
0.77.0 0 / 12
0.76.0 0 / 11
0.75.1 0 / 11
0.75.0 0 / 11
0.74.0 0 / 11
0.73.0 0 / 11
0.72.0 0 / 11
0.71.1 0 / 11
0.71.0 0 / 11
0.70.1 0 / 11
0.70.0 0 / 11
0.69.0 0 / 9
0.68.0 0 / 9
0.67.0 0 / 9
0.66.0 0 / 9
0.65.0 0 / 9
0.63.0 0 / 9
0.62.0 0 / 9
0.61.0 0 / 9
0.60.0 0 / 9
0.59.0 0 / 9
0.58.0 0 / 8
0.57.0 0 / 8
0.56.1 0 / 8
0.56.0 0 / 8
0.55.0 0 / 8
0.54.0 0 / 8
0.53.0 0 / 8
0.52.0 0 / 8
0.51.0 0 / 8
0.50.0 0 / 8
0.49.0 0 / 8
0.48.0 0 / 8
0.47.0 0 / 8
0.46.0 0 / 8
0.45.0 0 / 8
0.44.0 0 / 7
0.43.0 0 / 7
0.42.1 0 / 7
0.42.0 0 / 7
0.41.0 0 / 7
0.40.0 0 / 7
0.39.0 0 / 7
0.38.0 0 / 7
0.37.0 0 / 7
0.36.0 0 / 7
0.35.0 0 / 7
0.34.0 0 / 7
0.33.0 0 / 7
0.32.0 0 / 7
0.30.1 1 / 6
0.30.0 1 / 6
0.29.0 1 / 6
0.28.0 1 / 6
0.27.0 1 / 6
0.25.2 1 / 6
0.25.1 1 / 6
0.25.0 1 / 6
0.23.1 1 / 6
0.23.0 1 / 6
0.22.0 1 / 6
0.21.1 1 / 6
0.21.0 1 / 6
0.20.4 1 / 6
Showing 100 of 138 Next page →

v0.94.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.7

3 findings
HIGH New file with network + code execution: dist/chunk-7HH22XN4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-o0TzS7Ms.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.6

3 findings
HIGH New file with network + code execution: dist/chunk-GKZ6DFDN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-pOGZuYS7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.5

3 findings
HIGH New file with network + code execution: dist/chunk-GKZ6DFDN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-pOGZuYS7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.4

3 findings
HIGH New file with network + code execution: dist/chunk-SDR45ZQB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-pOGZuYS7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.3

3 findings
HIGH New file with network + code execution: dist/chunk-7PSFJTJZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DzXsfxre.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.2

3 findings
HIGH New file with network + code execution: dist/chunk-L4CACVIJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CdU8LyvB.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.1

3 findings
HIGH New file with network + code execution: dist/chunk-D336OZHK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-B3ZuApR_.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.94.0

3 findings
HIGH New file with network + code execution: dist/chunk-OO4EK3JB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-EGoRbbsd.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.93.2

3 findings
HIGH New file with network + code execution: dist/chunk-6K5CI33W.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxJ83oZA.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.93.1

3 findings
HIGH New file with network + code execution: dist/chunk-BVVRQ4YC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxJ83oZA.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.93.0

3 findings
HIGH New file with network + code execution: dist/chunk-BVVRQ4YC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxJ83oZA.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.92.1

3 findings
HIGH New file with network + code execution: dist/chunk-BVVRQ4YC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxJ83oZA.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.92.0

5 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.

HIGH New file with network + code execution: dist/chunk-I7WVPJBZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxJ83oZA.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: drewstone.

INFO Publisher changed: GitHub Actions → drewstone (on 2026-07-11, known maintainer) provenance

This version was published by a different npm account (drewstone) than the most recent previously approved version (GitHub Actions) on 2026-07-11, but drewstone is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.91.0

3 findings
HIGH New file with network + code execution: dist/chunk-AD7JW4QG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-rRj5hjJK.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.90.1

3 findings
HIGH New file with network + code execution: dist/chunk-ZV4LXYCJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-rRj5hjJK.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.90.0

3 findings
HIGH New file with network + code execution: dist/chunk-4IBAMGBE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DxHduZg7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.89.0

3 findings
HIGH New file with network + code execution: dist/chunk-PIPPLSOF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.88.0

3 findings
HIGH New file with network + code execution: dist/chunk-22HPUH77.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.87.0

3 findings
HIGH New file with network + code execution: dist/chunk-VKVNDNG4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.86.0

3 findings
HIGH New file with network + code execution: dist/chunk-3TZOXS7B.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.85.0

3 findings
HIGH New file with network + code execution: dist/chunk-DLAEEF26.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.84.0

3 findings
HIGH New file with network + code execution: dist/chunk-UJW6EVNY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.83.0

3 findings
HIGH New file with network + code execution: dist/chunk-QDVLTRCP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-CuDLO8wj.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.82.0

3 findings
HIGH New file with network + code execution: dist/chunk-JYURIKPF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BI9tpcmF.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.81.1

3 findings
HIGH New file with network + code execution: dist/chunk-D6GIWPKD.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BI9tpcmF.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.81.0

3 findings
HIGH New file with network + code execution: dist/chunk-SN3XBTTH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BI9tpcmF.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.80.1

3 findings
HIGH New file with network + code execution: dist/chunk-3RAXZ6LB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BI9tpcmF.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.80.0

3 findings
HIGH New file with network + code execution: dist/chunk-QSO2TVDS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BI9tpcmF.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.79.4

3 findings
HIGH New file with network + code execution: dist/chunk-AHZ3YBL6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-BFVtgRax.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.79.3

3 findings
HIGH New file with network + code execution: dist/chunk-AG335EXG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/coordination-DCmljYDf.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.