← Home

@teambit/mdx

45
Versions
SEE LICENSE IN UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:artifacts/env-template/public/252.3f8e3efaf164f42618f8.js AI (source-diff): Bundled library code, no malicious network+exec pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/252.3f8e3efaf164f42618f8.js AI (source-diff): Bundled sourcemap library code (source-map-js), not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/196.c85c0cb6551890749015.js AI (source-diff): Webpack-bundled preview artifact; long lines are minification, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/196.c85c0cb6551890749015.js AI (source-diff): Bundled config/runtime code, no concrete exfil/dropper behavior found. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.fb5f77e206b147352607.js AI (source-diff): Labeled bundler output explicitly, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/962.cdd4001d76ecb22df83c.js AI (source-diff): Bundled preview-module linking code, standard webpack minification. ai
source-diff obfuscated-file:artifacts/env-template/public/293.da3d813735dfb0eb19fd.js AI (source-diff): Webpack bundle of preview-modules linking code. ai
source-diff net-exec-file:artifacts/env-template/public/127.692a204f79deab30ab4d.js AI (source-diff): Bundled config/runner code, no malicious network+exec behavior found. ai
source-diff obfuscated-file:artifacts/env-template/public/127.692a204f79deab30ab4d.js AI (source-diff): Webpack bundle containing bit workspace config, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/109.a42f7d4992c0f39ccbb2.js AI (source-diff): Webpack bundle of floating-ui/react deps; minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/109.a42f7d4992c0f39ccbb2.js AI (source-diff): Bundled UI code, no fetched/executed remote payload observed. ai
dependencies unvetted-dep:@teambit/mdx.deps-detectors.detective-mdx AI (dependencies): Internal @teambit sibling package from same monorepo, not third-party. ai
source-diff net-exec-file:artifacts/env-template/public/peers.93f3f914ac4cf19596fd.js AI (source-diff): Bundled polyfill code, no malicious behavior identified. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.93f3f914ac4cf19596fd.js AI (source-diff): MDX scope provider + process shim bundle, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.6be45cfd54b830952f60.js AI (source-diff): Standard regenerator-runtime bundled output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.4eb504e6d746a04c0809.js AI (source-diff): Standard regenerator-runtime bundled output. ai
source-diff obfuscated-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/peers.77b26e09d61c5c00a1ce.js AI (source-diff): React/regenerator-runtime bundled code, no malicious network target. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.77b26e09d61c5c00a1ce.js AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.b48ccbde6f101db85546.js AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.25e4f1a3240e2f9babd6.js AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js AI (source-diff): Bundled Bit tooling config, not a dropper/loader payload. ai
source-diff obfuscated-file:artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo lockstep releases across many @teambit packages publish in quick succession routinely. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.6873fdc3eda19ebbc6e2.js AI (source-diff): Minified React bundle, not true obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/peers.6873fdc3eda19ebbc6e2.js AI (source-diff): React/MDX bundled preview chunk, false positive on bundler code. ai
source-diff net-exec-file:artifacts/env-template/public/753.633354a157780af09402.js AI (source-diff): Bit env-template runtime bootstrap, standard bundler pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/753.633354a157780af09402.js AI (source-diff): Webpack bundle containing Bit workspace config, not obfuscated malware. ai
source-diff obfuscated-file:artifacts/env-template/public/244.508e6438cc297ec46e93.js AI (source-diff): Webpack chunk bundle, minified not obfuscated; standard build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/490.2c6e78496df81fa1c838.js AI (source-diff): Bundled preview-module registry code, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/753.91f33c3481c1270c577d.js AI (source-diff): Bundled build config, no exfiltration behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e9d05aca21de4da81721.js AI (source-diff): Standard webpack/regenerator bundled output. ai
source-diff net-exec-file:artifacts/env-template/public/peers.de117b359495920da582.js AI (source-diff): Bundled preview UI code, no hostile behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.de117b359495920da582.js AI (source-diff): Bundled React/MDX preview code, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.9e68d56e82bc5e3e670a.js AI (source-diff): Standard webpack/regenerator bundled output. ai
source-diff obfuscated-file:artifacts/env-template/public/753.91f33c3481c1270c577d.js AI (source-diff): Bundled workspace config runner, dependency policy list, not malicious. ai
provenance no-provenance AI (provenance): Only ~12% of npm packages have provenance; not a signal for this established package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.b73062a555eba279b3d9.js AI (source-diff): Bundled webpack chunk, bundler banner confirmed. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.6829246e8fbfb4ac080f.js AI (source-diff): Bundled peer-exposure helper chunk, standard Bit env pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.aa2672ea50c8d370f2e3.js AI (source-diff): Bundled preview-module chunk. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are same-org (@teambit) and well-known (@mdx-js/mdx), consistent with package purpose. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.fa717c106187a693355f.js AI (source-diff): Webpack runtime bundle exposing peer deps globally; expected pattern for env-template. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.14ce4a81c9ed38fb10bc.js AI (source-diff): Confirmed bundled webpack output per finding detail. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.90059c3020abbc5ff352.js AI (source-diff): Webpack-bundled preview module, standard minified output. ai
source-diff net-exec-file:artifacts/env-template/public/976.131be05c5afb105432da.js AI (source-diff): Same bundled artifact; no evidence of malicious network/exec behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/976.131be05c5afb105432da.js AI (source-diff): Webpack-bundled preview chunk, bundler banner confirms build output not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/842.10f9ecaec2179c643f4f.js AI (source-diff): Bundled config/graphql code; no malicious network exfil found. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.b4b59df2f31ecb13e81f.js AI (source-diff): Standard webpack bundle output. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.8dd108d122a3b3c36981.js AI (source-diff): Standard webpack bundle output with regenerator-runtime. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.0d1b32f65ab6c189fcd3.js AI (source-diff): Webpack peer-exposure bundle, benign. ai
source-diff obfuscated-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js AI (source-diff): Webpack-bundled third-party UI libs (floating-ui etc.), not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js AI (source-diff): Bundled library code; no dropper/exfil behavior observed. ai
source-diff obfuscated-file:artifacts/env-template/public/842.10f9ecaec2179c643f4f.js AI (source-diff): Bundled bit workspace/dependency-resolver config, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/730.a1e9ab85da67cc746007.js AI (source-diff): Bundled workspace config/generators list, benign build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/596.45e99ecea308533db27c.js AI (source-diff): Bundled preview-modules linking code, benign. ai
source-diff net-exec-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js AI (source-diff): Bundled preview app code, no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js AI (source-diff): Webpack-bundled UI deps (floating-ui etc.), minified not obfuscated. ai
dependencies unvetted-dep:@teambit/mdx.compilers.mdx-multi-compiler AI (dependencies): First-party @teambit scoped package, part of monorepo. ai
source-diff net-exec-file:artifacts/env-template/public/peers.ef232665eb35edb9b131.js AI (source-diff): Bundled preview UI code, no malicious behavior confirmed. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.ef232665eb35edb9b131.js AI (source-diff): Bundled MDX/react preview code, minified only. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.279f3575aff65323889d.js AI (source-diff): Bundled webpack output, minified only. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.36031b005912b6d4fb6a.js AI (source-diff): Explicitly labeled bundled webpack output, minified only. ai
source-diff net-exec-file:artifacts/env-template/public/730.a1e9ab85da67cc746007.js AI (source-diff): Bundled config, no malicious destination identified. ai
source-diff obfuscated-file:artifacts/env-template/public/252.e92e777adf41980945e9.js AI (source-diff): Webpack-bundled UI preview chunk, minified not obfuscated malware. ai
npm-metadata no-description AI (npm-metadata): Monorepo sub-package convention across @teambit scope. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.992219c91e07f31f29a2.js AI (source-diff): Bundled peer-exposure shim for React/ReactDom, benign. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.2d55c2930dd8b1a171fa.js AI (source-diff): Bundled with regenerator-runtime banner, benign minified output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.cc2ff1c6def133d80ad4.js AI (source-diff): Bundled preview-modules chunk, benign. ai
source-diff obfuscated-file:artifacts/env-template/public/320.901d818bee5d1e4c5580.js AI (source-diff): MDX provider bundle, standard webpack output. ai
source-diff net-exec-file:artifacts/env-template/public/309.3c977db3e4de965b9b5a.js AI (source-diff): Bundled GraphQL/pnpm deps, new Function used in parser, benign. ai
source-diff obfuscated-file:artifacts/env-template/public/309.3c977db3e4de965b9b5a.js AI (source-diff): Bundled workspace config data, not obfuscation/malware. ai
source-diff net-exec-file:artifacts/env-template/public/252.e92e777adf41980945e9.js AI (source-diff): Bundled third-party libs (floating-ui etc.), no exfil behavior found. ai
source-diff net-exec-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js AI (source-diff): Bundled webpack chunk; no evidence of dropper/loader behavior in sample. ai
maintainer-change maintainer-removed AI (maintainer-change): Large trusted monorepo with frequent maintainer roster changes across 3211 versions. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d7dae3293a5e4691e8ad.js AI (source-diff): Peer dependency exposure bundle used by Bit's env-template preview system. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.1e6d937d5efb1b4aceb9.js AI (source-diff): Bundled regenerator-runtime polyfill code, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.6bbdbffe23c1f8fab208.js AI (source-diff): Preview module linking bundle, standard build output. ai
source-diff net-exec-file:artifacts/env-template/public/566.d36aee691774a6f7f55b.js AI (source-diff): Bundled config/workspace policy data, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/566.d36aee691774a6f7f55b.js AI (source-diff): Bundled workspace config data, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/320.762ef2b410b3d3456b80.js AI (source-diff): MDX react bundle, standard bundler output. ai
source-diff obfuscated-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js AI (source-diff): Webpack bundle chunk of third-party UI libs (floating-ui etc), not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/320.599b28259ac4e18100b7.js AI (source-diff): webpack chunk loader pattern; references only known Bit/pnpm/Babel packages, no exfiltration. ai
source-diff obfuscated-file:artifacts/env-template/public/198.68cd3ec0fa5f0952eabf.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/252.4d14d7a67940d51a45db.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/252.4d14d7a67940d51a45db.js AI (source-diff): webpack chunk loader pattern (__loadChunks_EnvTemplate/__webpack_require__); no external network calls to attacker infrastructure. ai
source-diff obfuscated-file:artifacts/env-template/public/320.599b28259ac4e18100b7.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e6769e7f300d23d324a2.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.6d7e2ec2d7d3104b12b8.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.994ad29cf3a2f35b0305.js AI (source-diff): Standard webpack minified browser bundle in Bit env-template preview artifacts; not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/peers.994ad29cf3a2f35b0305.js AI (source-diff): webpack chunk loader pattern; MDXScopeProvider/React content confirms legitimate preview bundle. ai
source-diff obfuscated-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js AI (source-diff): Standard webpack minified bundle in env-template artifacts; consistent with teambit's build output pattern. ai
source-diff net-exec-file:artifacts/env-template/public/peers.756261df050d3e99c4f4.js AI (source-diff): Webpack chunk loader pattern; no malicious network/exec behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.756261df050d3e99c4f4.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.2803be1e66624c3ae364.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.24063bd06a4c56ecf401.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/944.23c7a42c25b29314f834.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff net-exec-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Webpack chunk loader; references are to bit.dev static assets and known npm packages. ai
source-diff obfuscated-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff net-exec-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js AI (source-diff): Webpack chunk loader pattern; network refs are UI library imports, not malicious exfiltration. ai
source-diff net-exec-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js AI (source-diff): Webpack chunk loader pattern in browser preview bundle; not dropper malware. ai
source-diff net-exec-file:artifacts/env-template/public/peers.73a2a70dc18b1d8e71d5.js AI (source-diff): Webpack chunk loader in browser preview bundle; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.73a2a70dc18b1d8e71d5.js AI (source-diff): Webpack-minified peers bundle containing MDX/React; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.4b46b9c1c4152bb8c985.js AI (source-diff): Webpack-minified overview preview bundle; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.438cedd94ac2177b9dd5.js AI (source-diff): Webpack-minified compositions preview bundle; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/427.4ed003b9ce0af834c6f1.js AI (source-diff): Webpack-minified preview modules bundle; standard Bit build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js AI (source-diff): Webpack chunk loader in browser preview bundle; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js AI (source-diff): Webpack-minified env-template bundle with Bit workspace config; standard build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js AI (source-diff): Webpack-minified env-template preview bundle; standard Bit build artifact, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js AI (source-diff): Webpack module loading pattern in peers bundle; not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js AI (source-diff): Minified MDX/React peers bundle; contains recognizable React and MDX library code. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e5a9d86f138262d8248f.js AI (source-diff): Webpack overview chunk; same pattern as other env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.1d9cf133c5aed91d403c.js AI (source-diff): Webpack compositions chunk with regenerator-runtime; standard build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/874.3ef824f68e8be46dbe18.js AI (source-diff): Bit preview-modules bundle; minified but contains only preview registry logic. ai
source-diff net-exec-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js AI (source-diff): Webpack chunk; dynamic require is webpack's module system, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js AI (source-diff): Minified floating-ui + React bundle; standard build artifact for this package. ai
source-diff net-exec-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Webpack chunk for Bit env-template UI; network/exec patterns are webpack module loading, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Standard webpack bundle artifact; contains recognizable Bit/pnpm config data, not malicious obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/109.afe99e101a5dd2335ed5.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code, no malicious patterns. ai
source-diff net-exec-file:artifacts/env-template/public/peers.d53e72f98a5b329b689a.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d53e72f98a5b329b689a.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.7d24b9b1b1da5e262611.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.6eb8268f21046aae90cd.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff net-exec-file:artifacts/env-template/public/247.bc23f3269336c972f682.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/247.bc23f3269336c972f682.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/21.3ce949aa33ff0533d924.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff net-exec-file:artifacts/env-template/public/109.afe99e101a5dd2335ed5.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e0d3ce449a7f9203ff0d.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.9257550e2fa7739816e6.js AI (source-diff): Peer-exposure webpack bundle for MDX/React; benign pattern for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.b1913968613b03b7bbae.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
dependencies unvetted-dep:@teambit/mdx.modules.mdx-v3-options AI (dependencies): Internal @teambit org dependency; consistent with Bit component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.6ed4e3e819405b9a7fd4.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.062c9583b439f2b2b5eb.js AI (source-diff): Webpack-minified peers bundle for MDX preview; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.ef24cc09f4751b7b1b80.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Network refs and dynamic require are webpack runtime patterns in a UI preview bundle, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
dependencies unvetted-dep:@teambit/compilation.babel-compiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/mdx.compilers.mdx-transpiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/mdx.generator.mdx-templates AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.7b9f6f32612dab58bab5.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.30b56ae1163010055db6.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.aced30df8badbdd7db05.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.b6e0764847e828054c2e.js AI (source-diff): Standard webpack-minified peers bundle exposing MDX/React globals for Bit preview. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.4e4ad34a4323fd43d433.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.4330bdfb6f4fccfe70b2.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Network/exec pattern is webpack chunk loading infrastructure, not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Webpack chunk for browser preview; network+exec pattern is normal for bundled React/floating-ui code. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d540430f4886e3784624.js AI (source-diff): Webpack-minified peers bundle exposing MDX/React globals; standard Bit preview artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.7361db96144a51c87dd7.js AI (source-diff): Webpack-minified overview preview chunk; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.0e74eaf69c98639a8a38.js AI (source-diff): Webpack-minified compositions preview chunk; standard Bit build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack chunk; network+exec pattern is normal for bundled Bit preview runtime. ai
source-diff obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack-minified Bit workspace config chunk; benign build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Standard webpack-minified env-template preview artifact from Bit platform build; not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; normal build artifact pattern for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.996dd704600f74efbd9c.js AI (source-diff): Bit peers webpack bundle exposing MDX/React globals; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e8075062d68cc6943352.js AI (source-diff): Bit preview overview webpack bundle; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.f3373c8329e4a5918c3e.js AI (source-diff): Bit preview module webpack bundle; standard minified artifact for this package. ai
source-diff net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Webpack chunk with __webpack_require__; normal build artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Standard webpack-minified build artifact; floating-ui library bundle, not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Standard webpack-minified build artifact from Bit env-template preview; not obfuscated malware. ai
source-diff net-exec-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Network+exec pattern is webpack chunk loader for browser preview; not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3ef6b90dc602a054aabe.js AI (source-diff): Webpack-bundled peers bundle for MDX preview; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.a886de91d07252076cec.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.8f29dc4eddb40b49c603.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for teambit env-template public assets. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@teambit/typescript.modules.ts-config-mutator AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/helper-plugin-test-runner AI (phantom-deps): Test runner loaded by convention; stable false positive. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): Scoped @teambit package; levenshtein match to mobx is a false positive. ai
phantom-deps phantom-dep:@teambit/typescript AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in a webpack bundle artifact; expected pattern for bundled JS environments. ai

Versions (showing 45 of 45)

Version Deps Published
1.0.1073 27 / 9
1.0.1065 26 / 9
1.0.1061 26 / 9
1.0.1057 26 / 9
1.0.1055 26 / 9
1.0.1019 26 / 9
1.0.1014 25 / 9
1.0.995 37 / 11
1.0.982 37 / 11
1.0.980 37 / 11
1.0.975 37 / 11
1.0.972 37 / 11
1.0.970 37 / 11
1.0.969 37 / 11
1.0.968 37 / 11
1.0.957 37 / 11
1.0.956 37 / 11
1.0.952 37 / 11
1.0.951 37 / 11
1.0.949 37 / 11
1.0.939 37 / 11
1.0.867 37 / 11
1.0.861 37 / 11
1.0.860 37 / 11
1.0.817 36 / 11
1.0.798 36 / 11
1.0.631 36 / 11
1.0.630 36 / 11
1.0.629 36 / 11
1.0.628 36 / 11
1.0.627 36 / 11
1.0.626 36 / 11
1.0.625 36 / 11
1.0.624 36 / 11
1.0.621 36 / 11
1.0.619 36 / 11
1.0.617 36 / 11
1.0.615 36 / 11
1.0.611 36 / 11
1.0.588 36 / 11
1.0.578 36 / 11
1.0.510 35 / 10
1.0.508 35 / 10
1.0.333 35 / 10
1.0.295 35 / 10

v1.0.1073

10 findings
HIGH New obfuscated file: artifacts/env-template/public/109.a42f7d4992c0f39ccbb2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/109.a42f7d4992c0f39ccbb2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/127.692a204f79deab30ab4d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/127.692a204f79deab30ab4d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/293.da3d813735dfb0eb19fd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.4eb504e6d746a04c0809.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.6be45cfd54b830952f60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.93f3f914ac4cf19596fd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.93f3f914ac4cf19596fd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1065

8 findings
HIGH New obfuscated file: artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/611.2e7acbee3ea0502837ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/611.2e7acbee3ea0502837ad.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.25e4f1a3240e2f9babd6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.b48ccbde6f101db85546.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.77b26e09d61c5c00a1ce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.77b26e09d61c5c00a1ce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1061

8 findings
HIGH New obfuscated file: artifacts/env-template/public/244.508e6438cc297ec46e93.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/753.633354a157780af09402.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/753.633354a157780af09402.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.9ca001ede4b0d2fbf3ca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.749c055ebd171ff96b59.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.6873fdc3eda19ebbc6e2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.6873fdc3eda19ebbc6e2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1057

10 findings
HIGH New obfuscated file: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/490.2c6e78496df81fa1c838.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/753.91f33c3481c1270c577d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/753.91f33c3481c1270c577d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.e9d05aca21de4da81721.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.9e68d56e82bc5e3e670a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.de117b359495920da582.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.de117b359495920da582.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1055

10 findings
HIGH New obfuscated file: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/596.45e99ecea308533db27c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/730.a1e9ab85da67cc746007.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/730.a1e9ab85da67cc746007.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.36031b005912b6d4fb6a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.279f3575aff65323889d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.ef232665eb35edb9b131.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.ef232665eb35edb9b131.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.867

6 findings
HIGH New obfuscated file: artifacts/env-template/public/976.131be05c5afb105432da.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/976.131be05c5afb105432da.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.90059c3020abbc5ff352.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.14ce4a81c9ed38fb10bc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.fa717c106187a693355f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.861

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/842.10f9ecaec2179c643f4f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/842.10f9ecaec2179c643f4f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.b4b59df2f31ecb13e81f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.8dd108d122a3b3c36981.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.0d1b32f65ab6c189fcd3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.860

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/842.10f9ecaec2179c643f4f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/842.10f9ecaec2179c643f4f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.aa2672ea50c8d370f2e3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.b73062a555eba279b3d9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.6829246e8fbfb4ac080f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.817

9 findings
HIGH New obfuscated file: artifacts/env-template/public/252.e92e777adf41980945e9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.e92e777adf41980945e9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/309.3c977db3e4de965b9b5a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/309.3c977db3e4de965b9b5a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/320.901d818bee5d1e4c5580.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.cc2ff1c6def133d80ad4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.2d55c2930dd8b1a171fa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.992219c91e07f31f29a2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.798

9 findings
HIGH New obfuscated file: artifacts/env-template/public/252.041540aaf75a9dc05f44.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.041540aaf75a9dc05f44.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/320.762ef2b410b3d3456b80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/566.d36aee691774a6f7f55b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/566.d36aee691774a6f7f55b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.6bbdbffe23c1f8fab208.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.1e6d937d5efb1b4aceb9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.d7dae3293a5e4691e8ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.615

7 findings
HIGH New obfuscated file: artifacts/env-template/public/196.c85c0cb6551890749015.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/196.c85c0cb6551890749015.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/252.3f8e3efaf164f42618f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.3f8e3efaf164f42618f8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/962.cdd4001d76ecb22df83c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/peers.fb5f77e206b147352607.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.588

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.578

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.510

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.508

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.333

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.295

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.