← Home

@teambit/mdx

17
Versions
SEE LICENSE IN UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:artifacts/env-template/public/overview.b1913968613b03b7bbae.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e0d3ce449a7f9203ff0d.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.9257550e2fa7739816e6.js AI (source-diff): Peer-exposure webpack bundle for MDX/React; benign pattern for this package. ai
dependencies unvetted-dep:@teambit/mdx.modules.mdx-v3-options AI (dependencies): Internal @teambit org dependency; consistent with Bit component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.6ed4e3e819405b9a7fd4.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.ef24cc09f4751b7b1b80.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.062c9583b439f2b2b5eb.js AI (source-diff): Webpack-minified peers bundle for MDX preview; legitimate Bit platform build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Network refs and dynamic require are webpack runtime patterns in a UI preview bundle, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
dependencies unvetted-dep:@teambit/mdx.generator.mdx-templates AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/mdx.compilers.mdx-transpiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/compilation.babel-compiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.7b9f6f32612dab58bab5.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.30b56ae1163010055db6.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.aced30df8badbdd7db05.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.b6e0764847e828054c2e.js AI (source-diff): Standard webpack-minified peers bundle exposing MDX/React globals for Bit preview. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.4e4ad34a4323fd43d433.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.4330bdfb6f4fccfe70b2.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Network/exec pattern is webpack chunk loading infrastructure, not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.0e74eaf69c98639a8a38.js AI (source-diff): Webpack-minified compositions preview chunk; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Standard webpack-minified env-template preview artifact from Bit platform build; not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Webpack chunk for browser preview; network+exec pattern is normal for bundled React/floating-ui code. ai
source-diff obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack-minified Bit workspace config chunk; benign build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack chunk; network+exec pattern is normal for bundled Bit preview runtime. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.7361db96144a51c87dd7.js AI (source-diff): Webpack-minified overview preview chunk; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d540430f4886e3784624.js AI (source-diff): Webpack-minified peers bundle exposing MDX/React globals; standard Bit preview artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Standard webpack-minified build artifact from Bit env-template preview; not obfuscated malware. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.996dd704600f74efbd9c.js AI (source-diff): Bit peers webpack bundle exposing MDX/React globals; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e8075062d68cc6943352.js AI (source-diff): Bit preview overview webpack bundle; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.f3373c8329e4a5918c3e.js AI (source-diff): Bit preview module webpack bundle; standard minified artifact for this package. ai
source-diff net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Webpack chunk with __webpack_require__; normal build artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Standard webpack-minified build artifact; floating-ui library bundle, not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; normal build artifact pattern for this package. ai
source-diff net-exec-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Network+exec pattern is webpack chunk loader for browser preview; not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3ef6b90dc602a054aabe.js AI (source-diff): Webpack-bundled peers bundle for MDX preview; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.a886de91d07252076cec.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.8f29dc4eddb40b49c603.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for teambit env-template public assets. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in a webpack bundle artifact; expected pattern for bundled JS environments. ai
phantom-deps phantom-dep:@teambit/typescript.modules.ts-config-mutator AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/helper-plugin-test-runner AI (phantom-deps): Test runner loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@teambit/typescript AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dependency; stable false positive for this package. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): Scoped @teambit package; levenshtein match to mobx is a false positive. ai

Versions (showing 17 of 17)

Version Deps Published
1.0.982 37 / 11
1.0.980 37 / 11
1.0.975 37 / 11
1.0.972 37 / 11
1.0.970 37 / 11
1.0.969 37 / 11
1.0.968 37 / 11
1.0.957 37 / 11
1.0.956 37 / 11
1.0.952 37 / 11
1.0.951 37 / 11
1.0.949 37 / 11
1.0.939 37 / 11
1.0.631 36 / 11
1.0.628 36 / 11
1.0.625 36 / 11
1.0.624 36 / 11

v1.0.982

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/271.8983b12775e9c1379e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/271.8983b12775e9c1379e11.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.0e74eaf69c98639a8a38.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.7361db96144a51c87dd7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.d540430f4886e3784624.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.980

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/760.847613853bcbcc911626.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/760.847613853bcbcc911626.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.ef24cc09f4751b7b1b80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.6ed4e3e819405b9a7fd4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.062c9583b439f2b2b5eb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.975

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.4330bdfb6f4fccfe70b2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.4e4ad34a4323fd43d433.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.b6e0764847e828054c2e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.972

8 findings
HIGH New obfuscated file: artifacts/env-template/public/372.747516dd003c8cd1f1c0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/372.747516dd003c8cd1f1c0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.f3373c8329e4a5918c3e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.e8075062d68cc6943352.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.996dd704600f74efbd9c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

6 findings
HIGH New obfuscated file: artifacts/env-template/public/382.565b03c5d3748e06fc46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/382.565b03c5d3748e06fc46.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.8f29dc4eddb40b49c603.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.a886de91d07252076cec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.3ef6b90dc602a054aabe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.969

4 findings
HIGH New obfuscated file: artifacts/env-template/public/compositions.e0d3ce449a7f9203ff0d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.b1913968613b03b7bbae.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.9257550e2fa7739816e6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.957

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.956

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.952

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.951

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.949

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.939

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.631

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.628

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.625

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.624

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.