← Home

@teambit/ui

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Keywords

bitbit-aspectbit-core-aspectcomponentscollaborationweb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js AI (source-diff): Webpack-bundled UI asset, minified not obfuscated; stable pattern for this package's artifacts. ai
publish-pattern rapid-publish AI (publish-pattern): Monorepo with 3460 versions publishes frequently in short succession; expected cadence. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js AI (source-diff): Same bundled artifact duplicated across workspace/scope builds. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js AI (source-diff): Same bundled artifact duplicated across workspace/scope builds. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js AI (source-diff): Bundled graphlib/layout code; network+eval pattern is generic bundler output, no malicious target. ai
dependencies unvetted-dep:@teambit/design.themes.theme-toggler AI (dependencies): First-party @teambit monorepo dependency. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in webpack bundle runtime loader, standard bundler pattern not obfuscation. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): First-party @teambit monorepo dependency. ai
npm-metadata no-description AI (npm-metadata): Established package; missing description is cosmetic, not a malware signal. ai
provenance no-provenance AI (provenance): Only ~12% of npm packages have provenance; not a disqualifier for established packages. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js AI (source-diff): Webpack-bundled minified UI asset, not obfuscation; recurring pattern for this package's build artifacts. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js AI (source-diff): Bundled frontend code; benign for this package's build pipeline. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js AI (source-diff): Webpack-bundled minified UI asset, not obfuscation. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js AI (source-diff): Bundled frontend code; net+eval patterns are standard webpack runtime, not a dropper. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js AI (source-diff): Same bundled asset pattern, mirrored workspace build. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js AI (source-diff): Same bundled asset pattern, mirrored workspace build. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js AI (source-diff): Bundled UI code; sample shows layout library, no exfil behavior. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js AI (source-diff): Webpack-bundled UI asset (dagre/graphlib), minified not obfuscated. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js AI (source-diff): Same bundled webpack chunk pattern as sibling artifact. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js AI (source-diff): Webpack-bundled UI static asset, not obfuscation; large minified chunk is expected build output. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js AI (source-diff): Bundled webpack chunk (graphlib/layout libs), no evidence of dropper/loader behavior. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js AI (source-diff): Same bundled webpack chunk pattern as sibling artifact. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js AI (source-diff): Bundled webpack chunk false-positive; no malicious behavior in sample. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js AI (source-diff): Webpack-bundled UI build artifact; sample shows legitimate graphlib/layout code, not obfuscation. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js AI (source-diff): Bundled webpack chunk false-positive; no malicious behavior in sample. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js AI (source-diff): Webpack-bundled UI build artifact; sample shows legitimate graphlib/layout code, not obfuscation. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.45ddbd22.js AI (source-diff): Browser bundle with network calls is normal for a UI framework package; not a dropper pattern. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/747.65bc0367.js AI (source-diff): Browser bundle with network calls is normal for a UI framework package; not a dropper pattern. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/747.65bc0367.js AI (source-diff): Standard webpack-minified UI bundle artifact; expected for @teambit/ui shipping pre-built browser assets. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.45ddbd22.js AI (source-diff): Standard webpack-minified UI bundle artifact; expected for @teambit/ui shipping pre-built browser assets. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/196.6ebaafb5.js AI (source-diff): Browser UI bundle; network calls and dynamic module loading are normal webpack chunk patterns, not dropper malware. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/248.7a08bbf9.js AI (source-diff): Browser UI bundle; network calls and dynamic module loading are normal webpack chunk patterns, not dropper malware. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/248.7a08bbf9.js AI (source-diff): Webpack-bundled UI artifact; minified JS is expected for @teambit/ui's pre-built browser bundles. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/196.6ebaafb5.js AI (source-diff): Webpack-bundled UI artifact; minified JS is expected for @teambit/ui's pre-built browser bundles. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/515.10d69c43.js AI (source-diff): Browser UI bundle with fetch/XHR and dynamic module loading is expected for this package's UI artifacts. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/515.10d69c43.js AI (source-diff): Standard webpack minified browser bundle artifact; pattern is stable across all versions of this package. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/913.6f89dc84.js AI (source-diff): Standard webpack minified browser bundle artifact; pattern is stable across all versions of this package. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/913.6f89dc84.js AI (source-diff): Browser UI bundle with fetch/XHR and dynamic module loading is expected for this package's UI artifacts. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/747.bfe65073.js AI (source-diff): Same webpack module loader pattern; not malicious. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.12051623.js AI (source-diff): Webpack chunk containing graphlib/layout code; standard minified build artifact for Bit's UI bundle. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/201.12051623.js AI (source-diff): Network calls and dynamic requires are webpack module loader patterns in a browser UI bundle, not dropper malware. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/747.bfe65073.js AI (source-diff): Identical webpack chunk pattern as workspace bundle; standard minified build artifact. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/754.9ab2c3f1.js AI (source-diff): Webpack bundle for browser UI; network calls and dynamic module loading are expected in this context. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/754.9ab2c3f1.js AI (source-diff): Standard webpack minified UI bundle for @teambit/ui; not obfuscation, consistent with prior releases. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/652.16d96174.js AI (source-diff): Webpack bundle for browser UI; network calls and dynamic module loading are expected in this context. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/652.16d96174.js AI (source-diff): Standard webpack minified UI bundle for @teambit/ui; not obfuscation, consistent with prior releases. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/232.013ebf4f.js AI (source-diff): Webpack UI bundle chunk; minified graphlib/dagre layout code, not malware. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/594.04fdc8e6.js AI (source-diff): Webpack module system pattern; net-exec signal is webpack require(), not a dropper. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/594.04fdc8e6.js AI (source-diff): Webpack UI bundle chunk; same graphlib content as workspace bundle, not malware. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/232.013ebf4f.js AI (source-diff): Webpack module system pattern; network+exec signal is webpack require(), not a dropper. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/ssr/57e0cc5db6a609b0.cjs AI (source-diff): SSR bundle artifact; minified React/TypeScript output, not obfuscated malware. ai
dependencies unvetted-dep:@teambit/api-reference.hooks.use-api-renderers AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/rspack.modules.generate-asset-manifest AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/harmony.modules.harmony-root-generator AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/base-react.themes.theme-switcher AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/design.themes.light-theme AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/design.themes.dark-theme AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/design.themes.base-theme AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/toolbox.crypto.sha1 AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/react.rendering.ssr AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:@teambit/legacy.constants AI (dependencies): First-party @teambit scoped package; consistent with this package's ecosystem. ai
dependencies unvetted-dep:http-proxy AI (dependencies): Well-known proxy library; stable dependency in this package's build toolchain. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/139.64a0671d.js AI (source-diff): Webpack bundle for browser UI; network+dynamic-require is normal for bundled frontend code in this package. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/139.64a0671d.js AI (source-diff): Standard webpack-minified UI bundle artifact; not obfuscation, stable pattern for this package. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/463.c56e9999.js AI (source-diff): Webpack bundle for browser UI; network+dynamic-require is normal for bundled frontend code in this package. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/463.c56e9999.js AI (source-diff): Standard webpack-minified UI bundle artifact; stable pattern for this package. ai
source-diff net-exec-file:artifacts/ui-bundle/scope/public/bit/static/js/383.8bcaf67a.js AI (source-diff): Network calls and dynamic requires are normal in a bundled browser UI; not dropper behavior. ai
source-diff obfuscated-file:artifacts/ui-bundle/scope/public/bit/static/js/383.8bcaf67a.js AI (source-diff): Webpack-minified UI bundle chunk; expected artifact for @teambit/ui across all versions. ai
source-diff net-exec-file:artifacts/ui-bundle/workspace/public/bit/static/js/522.7834818c.js AI (source-diff): Network calls and dynamic requires are normal in a bundled browser UI; not dropper behavior. ai
source-diff obfuscated-file:artifacts/ui-bundle/workspace/public/bit/static/js/522.7834818c.js AI (source-diff): Webpack-minified UI bundle chunk; expected artifact for @teambit/ui across all versions. ai
typosquat typosquat.levenshtein:yup AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'yup' is a false positive. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'qs' is a false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'joi' is a false positive. ai
typosquat typosquat.levenshtein:uuid AI (typosquat): Scoped @teambit/ui package; Levenshtein match to short unscoped names is a false positive. ai
phantom-deps phantom-dep:@teambit/isolator AI (phantom-deps): Same-org package; phantom-dep heuristic unreliable for monorepo sibling packages. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped runtime dep loaded by convention, not direct import. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @teambit/ui package; Levenshtein match to 'pg' is a false positive. ai
phantom-deps phantom-dep:sanitize.css AI (phantom-deps): CSS asset referenced by convention, not JS import. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): PostCSS referenced in build config; not directly imported in JS. ai
phantom-deps phantom-dep:sass AI (phantom-deps): CSS preprocessor referenced in webpack/rspack config; not directly imported in JS. ai
phantom-deps phantom-dep:less AI (phantom-deps): CSS preprocessor referenced in webpack/rspack config; not directly imported in JS. ai

Versions (showing 51 of 59)

View all versions
Version Deps Published
1.0.1064 67 / 8
1.0.1060 67 / 8
1.0.1055 67 / 8
1.0.1052 67 / 8
1.0.1051 67 / 8
1.0.1021 67 / 8
1.0.1013 67 / 8
1.0.1002 67 / 8
1.0.1000 67 / 8
1.0.999 67 / 8
1.0.995 67 / 8
1.0.993 67 / 8
1.0.992 67 / 8
1.0.989 67 / 8
1.0.988 67 / 8
1.0.986 67 / 8
1.0.983 67 / 8
1.0.982 67 / 8
1.0.979 67 / 8
1.0.975 67 / 8
1.0.972 67 / 8
1.0.971 67 / 8
1.0.970 67 / 8
1.0.969 67 / 8
1.0.968 67 / 8
1.0.965 67 / 8
1.0.964 67 / 8
1.0.962 67 / 8
1.0.958 67 / 8
1.0.954 67 / 8
1.0.950 67 / 8
1.0.943 67 / 8
1.0.937 67 / 8
1.0.935 67 / 8
1.0.931 67 / 8
1.0.930 67 / 8
1.0.929 67 / 8
1.0.927 67 / 8
1.0.925 67 / 8
1.0.921 67 / 8
1.0.920 67 / 8
1.0.916 67 / 8
1.0.914 67 / 8
1.0.913 67 / 8
1.0.891 64 / 8
1.0.873 77 / 11
1.0.858 77 / 11
1.0.856 77 / 11
1.0.840 77 / 11
1.0.827 77 / 11
1.0.824 77 / 11

v1.0.1064

5 findings
HIGH New obfuscated file: artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/scope/public/bit/static/js/746.5693958d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/workspace/public/bit/static/js/856.35cd36db.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

5 findings
HIGH New obfuscated file: artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/workspace/public/bit/static/js/263.3f8bce79.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/scope/public/bit/static/js/814.868fba5b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1055

5 findings
HIGH New obfuscated file: artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/scope/public/bit/static/js/505.bde6abb1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/workspace/public/bit/static/js/635.9f0f0617.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1052

5 findings
HIGH New obfuscated file: artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/scope/public/bit/static/js/505.91cef6dd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/workspace/public/bit/static/js/635.7bb8cc98.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1051

5 findings
HIGH New obfuscated file: artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/scope/public/bit/static/js/505.c64c9393.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/ui-bundle/workspace/public/bit/static/js/635.c3c59170.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.921

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.920

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.916

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.914

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.913

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.891

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.873

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.858

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.856

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.840

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.827

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.824

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.