@teambit/react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Only ~12% of npm packages have provenance; not a signal for this established package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/0.b0010e0449d723a593e0.js | AI (source-diff): Bundled webpack runtime; no fetched-binary or exfil behavior present. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.bf02225ab8591f26a3df.js | AI (source-diff): Bundled floating-ui chunk, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/546.534eacbf2f5c0e597a2e.js | AI (source-diff): Bundled preview-modules chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.bf02225ab8591f26a3df.js | AI (source-diff): Bundled build output; no malicious network destination. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.a006d608f29b9aa08508.js | AI (source-diff): Bundled preview asset; new Function use is standard React internals, no malicious target. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.866265f5d90e3f236a24.js | AI (source-diff): Bundled webpack chunk with regenerator-runtime, standard build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.45d417eb671fda59ea62.js | AI (source-diff): Bundled webpack chunk, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/0.b0010e0449d723a593e0.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.a006d608f29b9aa08508.js | AI (source-diff): Bundled React/MDX chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.36202d49df8dc5500b8a.js | AI (source-diff): Bundled chunk-loader pattern misidentified as net+exec dropper. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.dab832672efd840c4b85.js | AI (source-diff): Bundled chunk misidentified as dropper pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.dab832672efd840c4b85.js | AI (source-diff): Webpack bundled MDX/process-polyfill chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.eea093bd0397e0a53ca7.js | AI (source-diff): Webpack bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.7fdc6ee8c4b8b1e40c1d.js | AI (source-diff): Webpack bundled regenerator-runtime chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/48.f03f06b0a06b65596634.js | AI (source-diff): Bundled config chunk, false-positive net+exec pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/48.f03f06b0a06b65596634.js | AI (source-diff): Webpack bundled workspace/dep-resolver config chunk, not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/372.fb03c4d39c8387bb3bc3.js | AI (source-diff): Webpack bundled preview-modules chunk, standard minified output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.36202d49df8dc5500b8a.js | AI (source-diff): Webpack bundled vendor chunk (floating-ui), not true obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.e68cb53ddfa675a275a2.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.b3108dabd757a9c50422.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js | AI (source-diff): Bundled Bit CLI config data, no dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.e68cb53ddfa675a275a2.js | AI (source-diff): React runtime bundle, no dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.cf3fcde482f47efb82b0.js | AI (source-diff): Webpack-bundled preview chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/490.2c6e78496df81fa1c838.js | AI (source-diff): Bundled webpack chunk, standard preview module code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.1e1ec4e8dcec138cd847.js | AI (source-diff): Bundled webpack chunk, regenerator-runtime boilerplate. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.e6e9f157947bcc36c1e2.js | AI (source-diff): Bundled webpack chunk, standard React runtime code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.2f6caa636bf7d395e248.js | AI (source-diff): Bundled webpack chunk, React internals. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.2f6caa636bf7d395e248.js | AI (source-diff): Bundled UI artifact, no malicious network target. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/753.91f33c3481c1270c577d.js | AI (source-diff): Bundled UI artifact, no malicious destination. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/753.91f33c3481c1270c577d.js | AI (source-diff): Bundled webpack chunk containing package's own dependency policy config. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.9e2b43335b16a04c2929.js | AI (source-diff): React/MDX bundled chunk. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.9e2b43335b16a04c2929.js | AI (source-diff): Bundled React code, new Function usage is React internals not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.5c799bd23e902beb2c2d.js | AI (source-diff): Bundled regenerator-runtime/babel helper code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.7525fc03c0741532fc6c.js | AI (source-diff): Bundled regenerator-runtime/babel helper code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/368.7f4510ee81e9120e0b0a.js | AI (source-diff): Webpack preview-modules bundle chunk. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js | AI (source-diff): Bundled webpack chunk running internal bit config, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js | AI (source-diff): Webpack bundle chunk for env-template preview artifact, not true obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js | AI (source-diff): Bundled artifact; env config payload, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js | AI (source-diff): Bundled build artifact, bit config data not malicious code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/586.3b2f16376c69f7f926c8.js | AI (source-diff): Webpack bundled preview module. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.2c43f45d17c35d2a5350.js | AI (source-diff): Bundled build output confirmed by label. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.a4d06f1ac5d93c105d65.js | AI (source-diff): Bundled build output confirmed by label. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.d3030da1838ffdad845f.js | AI (source-diff): React vendor bundle chunk, webpack banner present. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.d3030da1838ffdad845f.js | AI (source-diff): Bundled React runtime; no exfil destination shown. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Long-standing internal monorepo package, stable FP. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/272.a322a2d23ee688152059.js | AI (source-diff): Webpack-bundled preview module code, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.ee385e300a8d5097edc1.js | AI (source-diff): Bundled vendor code (floating-ui etc), no fetched/executed payload. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.ee385e300a8d5097edc1.js | AI (source-diff): Webpack-bundled preview build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.7e02206083a1149f750e.js | AI (source-diff): Bundled React runtime, no malicious behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.7e02206083a1149f750e.js | AI (source-diff): Bundled React vendor code, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.ed11159c361064a003c6.js | AI (source-diff): Bundled preview module output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.856d745e11b28bd8c839.js | AI (source-diff): Bundled preview module output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/532.791c06c5b2e77eaf5fbb.js | AI (source-diff): Bundled build config, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/532.791c06c5b2e77eaf5fbb.js | AI (source-diff): Webpack-bundled config/policy bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.711bcdbcdc73a2421711.js | AI (source-diff): Webpack-bundled regenerator-runtime chunk. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo with lockstep versioning across many teambit packages; frequent releases are routine. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.e761ba54734b91bec00a.js | AI (source-diff): Bundled React runtime, no malicious exfil target. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.e761ba54734b91bec00a.js | AI (source-diff): Bundled React/MDX chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.0a9a9c4a5f818b6f4a51.js | AI (source-diff): Webpack-bundled chunk, same pattern. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/753.633354a157780af09402.js | AI (source-diff): Bundled workspace config, benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/753.633354a157780af09402.js | AI (source-diff): Bundled bit workspace config chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js | AI (source-diff): Bundled build config, no fetch/exec toward unrelated destination. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js | AI (source-diff): Webpack-bundled floating-ui chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/244.508e6438cc297ec46e93.js | AI (source-diff): Webpack-bundled preview app chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.ffa1eb67938657196e04.js | AI (source-diff): Minified webpack bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.7994ff0c017da9ecb5c4.js | AI (source-diff): Webpack chunk-loading boilerplate, no real network exfil target. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/553.616ef114bdea8ed4aba5.js | AI (source-diff): Bundled build config data, not obfuscated code. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/553.616ef114bdea8ed4aba5.js | AI (source-diff): Webpack runtime boilerplate, standard for bundled preview app. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.14d19895bc8e530a7717.js | AI (source-diff): Minified webpack bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.1ba7c745d276c00033e5.js | AI (source-diff): Minified webpack bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.7994ff0c017da9ecb5c4.js | AI (source-diff): Webpack bundle output for env-template preview UI, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.4759dd2ce4aacfcbfe21.js | AI (source-diff): Webpack-bundled UI preview asset, minified not obfuscated; recurring in this build system. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.4759dd2ce4aacfcbfe21.js | AI (source-diff): Bundled browser UI code (floating-ui etc), no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.0e953aaa944b1b1eebcd.js | AI (source-diff): Bundled preview-app output, standard for this component's env-template artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.4c5bfd6dd4fadc542afe.js | AI (source-diff): Bundled preview-app output, standard for this component's env-template artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.deaff551d09daade70ea.js | AI (source-diff): Bundled peer-exposure shim for webpack, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.97d2cec28b304058eca8.js | AI (source-diff): Bundled MDX/react chunk, minified build output only. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js | AI (source-diff): Webpack-bundled vendor chunk (floating-ui/react), not true obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js | AI (source-diff): Webpack module loader machinery, no fetched/executed payload. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/454.16b97ec63276f3ee67b6.js | AI (source-diff): Bundled preview-modules chunk, minified build output only. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/947.e27a9b7fe96a64000661.js | AI (source-diff): Bundled config/policy chunk for env-template, not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/947.e27a9b7fe96a64000661.js | AI (source-diff): Webpack chunk init code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.5440e2c4a3e12c705422.js | AI (source-diff): Bundled regenerator-runtime/react output, standard build artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.0fe47c106a6dcbe3739a.js | AI (source-diff): Bundled preview chunk, minified build output only. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.97d2cec28b304058eca8.js | AI (source-diff): Webpack loader code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.30e4375690d90355d885.js | AI (source-diff): Bundled webpack/regenerator-runtime code, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.b6a2e98e40e92d9e2f75.js | AI (source-diff): Bundled peer-exposure shim for preview iframe, standard Bit pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/37.e820dd89ea85eea5203c.js | AI (source-diff): Bundled webpack chunk containing Bit's own dependency policy JSON. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/37.e820dd89ea85eea5203c.js | AI (source-diff): Bundled preview app code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.f881028e713f06188ec7.js | AI (source-diff): Bundled webpack chunk, standard preview module code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.a5815a9be36e669fa6d4.js | AI (source-diff): Webpack-bundled preview asset, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.4f6323c667baa87bc113.js | AI (source-diff): Webpack-bundled preview asset, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.e22312f178039c597d0d.js | AI (source-diff): Webpack-bundled preview asset, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/596.5219fbf70877df73c101.js | AI (source-diff): Bundled config JSON + webpack runtime, no remote code execution present. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.25a3deb8b259fb073602.js | AI (source-diff): Webpack-bundled preview UI artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.62f8ac9101df47502d01.js | AI (source-diff): Webpack-bundled preview UI artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.2226aeba48931086f971.js | AI (source-diff): Webpack-bundled preview UI artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/596.5219fbf70877df73c101.js | AI (source-diff): Webpack-bundled preview UI artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.cb1a30fb22cebc50c541.js | AI (source-diff): Webpack-bundled UI artifact, not obfuscation; standard for this monorepo's build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.a1c6a0dd5478d86bfae2.js | AI (source-diff): Webpack-bundled UI artifact, not obfuscation; standard for this monorepo's build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.6332985ba40ed463e06b.js | AI (source-diff): Webpack-bundled UI artifact, not obfuscation; standard for this monorepo's build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.86d17a209c7a69880780.js | AI (source-diff): Webpack chunk loader pattern, not a dropper; matches package's build-output nature. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.86d17a209c7a69880780.js | AI (source-diff): Webpack bundle output, not true obfuscation; standard for env-template artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/517.438a73130acbb9db2240.js | AI (source-diff): Bundled build output, config data embedded, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.fa9d281cb67bd67d7b14.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.e886cd1acbbe20907c90.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.cd28e65715ff27b22255.js | AI (source-diff): Bundled build output; peer-exposure helper, not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/517.438a73130acbb9db2240.js | AI (source-diff): Webpack chunk loader pattern, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.0eea930b6b8e5fe53ac6.js | AI (source-diff): Webpack-bundled preview artifact; minification is expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.a6d6e99a84555197511e.js | AI (source-diff): Webpack-bundled preview artifact; minification is expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.2c384422e765a31fac47.js | AI (source-diff): Webpack-bundled preview artifact; minification is expected. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/869.958be3d72c5fa88af634.js | AI (source-diff): Webpack chunk; network refs are static.bit.dev icon URLs, not exfiltration. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/869.958be3d72c5fa88af634.js | AI (source-diff): Webpack-minified artifact with readable bit workspace config; benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.c7e36cdd3c42040554fa.js | AI (source-diff): Webpack peer-deps bundle exposing React/MDX globals; benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.6259f25f5a40cbbcc25a.js | AI (source-diff): Minified webpack bundle containing regenerator-runtime; benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.aec63f8441f7d765a7d0.js | AI (source-diff): Minified webpack bundle for bit preview modules; benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js | AI (source-diff): Webpack-minified bundle of floating-ui and other legitimate libs; stable pattern for this package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js | AI (source-diff): Webpack chunk with __webpack_require__; standard module loader pattern, not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/348.c7479d1547f3ca674a78.js | AI (source-diff): Webpack-minified Bit preview module bundle; legitimate artifact. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js | AI (source-diff): Webpack __webpack_require__ loader; standard bundler pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js | AI (source-diff): Webpack chunk containing Bit workspace config and dependency policy; legitimate env-template artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.78c59da098870d01e0ff.js | AI (source-diff): Webpack-minified compositions preview bundle; legitimate artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.271d021343ea625b0dd7.js | AI (source-diff): Webpack-minified overview preview bundle; legitimate artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.cbe9e3950091006fcee3.js | AI (source-diff): Webpack-minified peers bundle with React and MDX; legitimate artifact. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.cbe9e3950091006fcee3.js | AI (source-diff): Webpack __webpack_require__ loader pattern; not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js | AI (source-diff): Standard webpack-minified browser chunk in Bit env-template preview artifacts; not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.903d74bba0ad71e6af5a.js | AI (source-diff): Minified webpack chunk in env-template preview artifacts; benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/427.4ed003b9ce0af834c6f1.js | AI (source-diff): Minified webpack chunk in env-template preview artifacts; benign. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js | AI (source-diff): Webpack chunk with __webpack_require__; normal browser bundle pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js | AI (source-diff): Minified webpack chunk in env-template preview artifacts; benign. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js | AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; normal browser bundle pattern for Bit preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.e8dabe4bcdf6b4d853c8.js | AI (source-diff): Minified webpack chunk in env-template preview artifacts; benign. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.e8dabe4bcdf6b4d853c8.js | AI (source-diff): Webpack chunk with __webpack_require__; normal browser bundle pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.d1d98d5096bf2a0ac8b8.js | AI (source-diff): Minified webpack chunk in env-template preview artifacts; benign. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): Same-org @teambit scope; stable dependency pattern across all teambit package versions. | ai | |
| dependencies | unvetted-dep:@bitdev/react.generators.react-templates | AI (dependencies): Bitdev org; expected generator dependency for React env. | ai | |
| dependencies | unvetted-dep:@teambit/typescript.typescript-compiler | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@bitdev/react.generators.react-starters | AI (dependencies): Bitdev org; expected generator dependency for React env. | ai | |
| dependencies | unvetted-dep:@teambit/defender.prettier-formatter | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@teambit/mdx.modules.mdx-v3-options | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@teambit/defender.eslint-linter | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@teambit/react.jest.react-jest | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@teambit/defender.jest-tester | AI (dependencies): Same-org @teambit scope; expected tooling dependency. | ai | |
| dependencies | unvetted-dep:@teambit/react.rendering.ssr | AI (dependencies): Same-org @teambit scope; expected for a React env package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/170.5ebe22fe14011720ade5.js | AI (source-diff): Standard webpack-minified preview bundle; content is recognizable Bit/React config, not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.6b1b60697f3e28ba5c36.js | AI (source-diff): Webpack chunk loader pattern; not a dropper/loader. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.6b1b60697f3e28ba5c36.js | AI (source-diff): Standard webpack-minified preview bundle containing floating-ui exports; not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/170.5ebe22fe14011720ade5.js | AI (source-diff): Webpack chunk loader pattern (__loadChunks_EnvTemplate); not a dropper/loader. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.6d5ae4c2598e535c4093.js | AI (source-diff): Minified peer-deps bundle exposing React/MDX namespaces; standard Bit env-template artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.61940026750fb3f63599.js | AI (source-diff): Minified Bit preview bundle with regenerator-runtime; standard build artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.95cb86e2f6284e3523f3.js | AI (source-diff): Minified Bit preview module bundle; content is recognizable PreviewModules class, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js | AI (source-diff): Webpack-minified browser bundle containing floating-ui/React OSS code. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js | AI (source-diff): Same bundle; network refs are webpack chunk-loading, not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js | AI (source-diff): Webpack-minified browser bundle for Bit env-template preview; not install-time code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.a6d430b9d865db143790.js | AI (source-diff): Webpack-minified overview preview bundle; same pattern as other env-template chunks. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.9f25b0374ec1200581c8.js | AI (source-diff): Webpack-minified peers bundle containing MDX/React OSS code. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.9f25b0374ec1200581c8.js | AI (source-diff): Same bundle; webpack chunk-loading, not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.4e73b0a476e90992b0d7.js | AI (source-diff): Webpack-minified compositions preview bundle; regenerator-runtime and React OSS code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/874.3ef824f68e8be46dbe18.js | AI (source-diff): Webpack-minified preview-modules bundle; legitimate Bit preview infrastructure. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js | AI (source-diff): Same bundle; webpack chunk-loading pattern, not malware. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jsx-a11y | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:@teambit/react.ui.highlighter.component-metadata.bit-component-meta | AI (phantom-deps): Same-org scope dependency used via config convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-hooks | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:jest-environment-jsdom | AI (phantom-deps): Jest config-referenced environment; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-import | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-mdx | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive. | ai | |
| phantom-deps | phantom-dep:sanitize.css | AI (phantom-deps): CSS utility referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:eslint-mdx | AI (phantom-deps): Config-referenced ESLint plugin; stable false positive for this React env package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.af03aaba01a119d50ce5.js | AI (source-diff): Standard webpack-minified preview artifact; consistent with teambit's build pipeline. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.22d017a8be7f3c8be0e6.js | AI (source-diff): Standard webpack-minified preview artifact; consistent with teambit's build pipeline. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js | AI (source-diff): Webpack chunk with __webpack_require__; no actual network exfiltration or shell exec. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js | AI (source-diff): Standard webpack-minified preview artifact; consistent with teambit's build pipeline. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.a2a592605d678eb6ce53.js | AI (source-diff): Standard webpack-minified preview artifact; consistent with teambit's build pipeline. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.56e24c8a295875b38458.js | AI (source-diff): Minified webpack bundle for Bit preview compositions; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.7c77d0e9d76d866c894c.js | AI (source-diff): Minified webpack bundle for Bit preview overview; standard build artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.9dc615dbdcb07a6bf514.js | AI (source-diff): Minified webpack bundle exposing peer deps to global scope; standard Bit preview pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.859255ebcaebf76e1a2c.js | AI (source-diff): Bit preview peers chunk; minified webpack output is expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.db9fb938116f91318c71.js | AI (source-diff): Bit preview overview chunk; minified webpack output is expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.2c65fb8e4f08e43a4792.js | AI (source-diff): Bit preview composition chunk; minified webpack output is expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.7c19924039daeeca6ea2.js | AI (source-diff): Minified preview chunk; readable PreviewModules class visible in sample. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.81c48e13b3eab3dc3043.js | AI (source-diff): Minified webpack chunk with regenerator-runtime; standard build artifact. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.b023eb5b83a8844e8985.js | AI (source-diff): Minified peer-deps bundle exposing React/ReactDom to global; expected pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js | AI (source-diff): Webpack-minified build artifact (Bit workspace config runner); stable pattern for this package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js | AI (source-diff): Minified webpack chunk; network+exec pattern is from bundled library code, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.1a326494cf7727444a63.js | AI (source-diff): Webpack-minified preview artifact; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.a3515c89b29e7ef25b3d.js | AI (source-diff): Webpack-minified preview artifact; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.55653caff840f84050af.js | AI (source-diff): Webpack-minified peer-deps bundle; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.7858520bd0f94a6128af.js | AI (source-diff): Standard webpack bundle artifact for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.baa89ef2ba9dd80c6aa0.js | AI (source-diff): Standard webpack bundle artifact for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.8abb69ea906301b64e68.js | AI (source-diff): Standard webpack bundle artifact for Bit env-template preview. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/187.4f9f6cd70b22ed88e42f.js | AI (source-diff): Webpack chunk loader pattern, not dropper malware; stable for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/187.4f9f6cd70b22ed88e42f.js | AI (source-diff): Standard webpack bundle artifact for Bit env-template preview; consistent with all prior @teambit releases. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.48fa6d1c9778931feaf8.js | AI (source-diff): Webpack-minified browser chunk in env-template preview artifacts; expected for this package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js | AI (source-diff): Webpack bundle with __webpack_require__; standard browser chunk, not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js | AI (source-diff): Webpack-minified browser chunk in env-template preview artifacts; expected for this package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js | AI (source-diff): Webpack bundle with __webpack_require__; standard browser chunk, not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js | AI (source-diff): Webpack-minified browser chunk in env-template preview artifacts; expected for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.dd602b612d6dcd528263.js | AI (source-diff): Webpack-minified browser chunk in env-template preview artifacts; expected for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.23cb3e212e6357189bcc.js | AI (source-diff): Webpack-minified browser chunk in env-template preview artifacts; expected for this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js | AI (source-diff): Webpack-bundled preview artifact; standard teambit env-template build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.52a942f3b8cd1951748b.js | AI (source-diff): Webpack-bundled preview artifact; standard teambit env-template build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.97b1450e3f8c72df33c6.js | AI (source-diff): Webpack-bundled preview artifact; standard teambit env-template build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.c60a2dea6aca09b86b9e.js | AI (source-diff): Webpack-bundled preview artifact; standard teambit env-template build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js | AI (source-diff): Webpack chunk with __webpack_require__; not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js | AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; not malicious dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js | AI (source-diff): Webpack-bundled preview artifact; standard teambit env-template build output across all versions. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.3510edef65cd1cab1358.js | AI (source-diff): Standard webpack bundle artifact for Bit's env-template preview; content is recognizable React/webpack runtime code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.0317868acc7f007a25d8.js | AI (source-diff): Standard webpack bundle artifact for Bit's env-template preview; content is recognizable React/webpack runtime code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.77706f3b6126e4aac8b3.js | AI (source-diff): Standard webpack bundle artifact for Bit's env-template preview; content is recognizable React/webpack runtime code. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped convention dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Known implicit binary dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Known implicit runtime dep; stable false positive. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in bundled webpack artifact; standard pattern for build/env tooling, not user-controlled input. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): Config-referenced peer tool; stable false positive for this env package. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Config-referenced peer tool; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/helper-plugin-test-runner | AI (phantom-deps): Framework-scoped convention dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Config-referenced peer tool for this React env package; stable false positive. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 1.0.1070 | 115 / 18 | |
| 1.0.1064 | 115 / 18 | |
| 1.0.1060 | 115 / 18 | |
| 1.0.1056 | 115 / 18 | |
| 1.0.1055 | 115 / 18 | |
| 1.0.1052 | 115 / 18 | |
| 1.0.1051 | 115 / 18 | |
| 1.0.1030 | 115 / 18 | |
| 1.0.1021 | 115 / 18 | |
| 1.0.1006 | 115 / 18 | |
| 1.0.996 | 115 / 18 | |
| 1.0.995 | 115 / 18 | |
| 1.0.990 | 115 / 18 | |
| 1.0.987 | 115 / 18 | |
| 1.0.986 | 115 / 18 | |
| 1.0.983 | 115 / 18 | |
| 1.0.982 | 115 / 18 | |
| 1.0.980 | 115 / 18 | |
| 1.0.979 | 115 / 18 | |
| 1.0.975 | 115 / 18 | |
| 1.0.974 | 115 / 18 | |
| 1.0.973 | 115 / 18 | |
| 1.0.972 | 115 / 18 | |
| 1.0.971 | 115 / 18 | |
| 1.0.970 | 115 / 18 | |
| 1.0.969 | 115 / 18 | |
| 1.0.967 | 115 / 18 | |
| 1.0.966 | 115 / 18 | |
| 1.0.962 | 115 / 18 | |
| 1.0.961 | 115 / 18 | |
| 1.0.958 | 115 / 18 | |
| 1.0.957 | 115 / 18 | |
| 1.0.956 | 115 / 18 | |
| 1.0.955 | 115 / 18 | |
| 1.0.951 | 114 / 18 | |
| 1.0.950 | 114 / 18 | |
| 1.0.949 | 114 / 18 | |
| 1.0.948 | 114 / 18 | |
| 1.0.947 | 114 / 18 | |
| 1.0.944 | 114 / 18 | |
| 1.0.943 | 114 / 18 | |
| 1.0.942 | 114 / 18 | |
| 1.0.941 | 114 / 18 | |
| 1.0.938 | 114 / 18 | |
| 1.0.937 | 114 / 18 | |
| 1.0.934 | 114 / 18 | |
| 1.0.933 | 114 / 18 | |
| 1.0.932 | 114 / 18 | |
| 1.0.931 | 114 / 18 | |
| 1.0.887 | 114 / 18 | |
| 1.0.883 | 114 / 18 |
v1.0.1070
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1064
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1056
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1055
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1052
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1051
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.990
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.887
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.883
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.