← Home

@upstash/redis

94
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mdoganbuggyhuntercahidardafahreddin.ozcanupstashnpmjoshtcburak-upsshannonr

Keywords

redisdatabaseserverlessedgeupstash

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:chunk-NSLIVMRY.js AI (source-diff): tsup bundle; fetch() targets user-configured Upstash baseUrl, no dynamic code exec. ai
source-diff net-exec-file:chunk-WAPWYB6L.mjs AI (source-diff): ESM bundle of same SDK requester; benign fetch to configured endpoint. ai
source-diff net-exec-file:chunk-5HXMXPOL.js AI (source-diff): tsup bundle of the REST requester; fetch is core function, no dynamic exec. ai
source-diff net-exec-file:zmscore-415f6c9f.d.ts AI (source-diff): TypeScript declaration file, no executable payload. ai
source-diff obfuscated-file:zmscore-415f6c9f.d.ts AI (source-diff): Readable .d.ts type defs; long type-export lines, not obfuscation. ai
source-diff net-exec-file-transition:cloudflare.mjs AI (source-diff): fetch to configured baseUrl, base64 decode; benign client logic. ai
source-diff obfuscated-file-transition:cloudflare.mjs AI (source-diff): tsup-bundled build output. ai
source-diff net-exec-file-transition:nodejs.js AI (source-diff): fetch to configured baseUrl; benign client logic. ai
source-diff net-exec-file-transition:fastly.mjs AI (source-diff): fetch to configured baseUrl; benign client logic. ai
source-diff obfuscated-file-transition:fastly.mjs AI (source-diff): tsup-bundled build output. ai
source-diff net-exec-file-transition:fastly.js AI (source-diff): fetch to configured baseUrl; benign client logic. ai
source-diff obfuscated-file-transition:fastly.js AI (source-diff): tsup-bundled build output. ai
phantom-deps phantom-dep:@biomejs/biome AI (phantom-deps): biome is a formatter referenced in config/scripts, not imported. ai
source-diff net-exec-file-transition:nodejs.mjs AI (source-diff): fetch to configured baseUrl; benign client logic. ai
source-diff obfuscated-file-transition:nodejs.mjs AI (source-diff): tsup-bundled build output. ai
source-diff obfuscated-file-transition:nodejs.js AI (source-diff): tsup-bundled build output. ai
source-diff obfuscated-file:zmscore-4382faf4.d.ts AI (source-diff): Large minified .d.ts type bundle, not obfuscation. ai
source-diff net-exec-file:chunk-DKKYFKP2.mjs AI (source-diff): Bundled REST client: fetch to user baseUrl + base64 decode of responses, not exec. ai
source-diff net-exec-file:chunk-OHFT7Y75.js AI (source-diff): tsup build output of same REST requester; benign. ai
source-diff net-exec-file:zmscore-4382faf4.d.ts AI (source-diff): TypeScript declaration file; no executable code. ai
source-diff obfuscated-file:zmscore-fa7fc9c8.d.ts AI (source-diff): Large generated .d.ts type declarations, not obfuscation. ai
source-diff net-exec-file:chunk-KXHOP7IA.js AI (source-diff): tsup bundle; same benign fetch/base64 requester code. ai
source-diff net-exec-file:chunk-ITYCTRXG.mjs AI (source-diff): tsup bundle; fetch to user-configured Upstash baseUrl, base64 is response decode not eval. ai
source-diff net-exec-file:zmscore-fa7fc9c8.d.ts AI (source-diff): TypeScript declaration file, no executable code. ai
source-diff net-exec-file:chunk-WDEZBVJF.js AI (source-diff): Bundled tsup dist chunk; fetch to user-configured Upstash baseUrl, base64 response decode. Benign build output. ai
source-diff net-exec-file:chunk-W3IXR5IB.mjs AI (source-diff): Bundled tsup dist chunk; same Upstash REST client code as .js variant. ai
source-diff net-exec-file:zmscore-07021e27.d.ts AI (source-diff): TypeScript declaration file, no executable code. ai
source-diff obfuscated-file:zmscore-07021e27.d.ts AI (source-diff): Long-line .d.ts type bundle; readable types, not obfuscation. ai
source-diff obfuscated-file-transition:cloudflare.d.ts AI (source-diff): Build-tool switch produced long-line generated .d.ts. ai
source-diff obfuscated-file-transition:nodejs.d.ts AI (source-diff): Build-tool switch produced long-line generated .d.ts. ai
source-diff obfuscated-file-transition:fastly.d.ts AI (source-diff): Build-tool switch produced long-line generated .d.ts. ai
source-diff obfuscated-file:nodejs.d.mts AI (source-diff): Generated type re-export file. ai
source-diff obfuscated-file:fastly.d.mts AI (source-diff): Generated type re-export file. ai
source-diff obfuscated-file:cloudflare.d.mts AI (source-diff): Generated type re-export file. ai
source-diff obfuscated-file:zmscore-b6b93f14.d.ts AI (source-diff): Long-line generated .d.ts, not obfuscation. ai
source-diff net-exec-file:zmscore-b6b93f14.d.ts AI (source-diff): Type-declaration file, no executable payload. ai
source-diff net-exec-file:chunk-SMBYCQIJ.js AI (source-diff): Same bundled REST client output, no hostile destination. ai
source-diff net-exec-file:chunk-I6BAFAQP.mjs AI (source-diff): tsup bundle; fetch to Upstash REST + atob response decode is core function. ai
source-diff obfuscated-file:zmscore-10fd3773.d.ts AI (source-diff): long-line TS type export file from bundler, benign ai
source-diff net-exec-file-transition:cloudflare.js AI (source-diff): fetch-based REST client in bundled dist; core function, no hostile destination ai
source-diff obfuscated-file-transition:cloudflare.js AI (source-diff): tsup-minified dist output, not obfuscation; stable build artifact for this package ai
source-diff net-exec-file:zmscore-10fd3773.d.ts AI (source-diff): type-def file; fetch is the client's stated function ai
provenance publisher-changed-stale AI (provenance): Long-stable historical publisher change, not a takeover indicator. ai
maintainer-change maintainer-added AI (maintainer-change): Same chronark transfer, long-established trusted publisher. ai
phantom-deps phantom-dep:encoding AI (phantom-deps): Known isomorphic-fetch/node-fetch dependency, not directly imported but legitimately required. ai
publish-pattern new-deps-added AI (publish-pattern): Adds well-known 'encoding' package tied to fetch polyfill, not a supply-chain risk here. ai
source-diff net-exec-file:chunk-7NCPWARK.mjs AI (source-diff): tsup bundle mjs variant; same client request logic. ai
source-diff net-exec-file:chunk-5IGN7AOR.js AI (source-diff): tsup bundle; fetch targets user-configured Upstash baseUrl, no dynamic exec. ai
source-diff obfuscated-file:zmscore-CjoCv9kz.d.mts AI (source-diff): TypeScript declaration file, long type lines from bundler; not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Bundling change in official package; no injected payload. ai
source-diff net-exec-file:zmscore-CjoCv9kz.d.ts AI (source-diff): .d.ts type declarations, not executable code. ai
source-diff obfuscated-file:zmscore-CjoCv9kz.d.ts AI (source-diff): TypeScript declaration file; long type lines are build artifacts. ai
source-diff net-exec-file:zmscore-CjoCv9kz.d.mts AI (source-diff): .d.mts type declarations, not executable code. ai
source-diff net-exec-file:chunk-5XANP4AV.mjs AI (source-diff): tsup-bundled dist output of legit client code; no hostile destination. ai
source-diff obfuscated-file:zmscore-hRk-rDLY.d.ts AI (source-diff): Long-line minified .d.ts type-declaration build output from tsup, not obfuscation. ai
source-diff net-exec-file:zmscore-hRk-rDLY.d.ts AI (source-diff): Type declaration file, no executable payload. ai
source-diff obfuscated-file:zmscore-hRk-rDLY.d.mts AI (source-diff): Long-line minified .d.ts type-declaration build output from tsup, not obfuscation. ai
source-diff net-exec-file:zmscore-hRk-rDLY.d.mts AI (source-diff): Type declaration file, no executable payload. ai
source-diff net-exec-file:chunk-TA73MYTP.mjs AI (source-diff): Bundled client dist; network is the Upstash REST API by design. ai
source-diff net-exec-file:chunk-JPMD56E6.js AI (source-diff): tsup-bundled client fetch logic; benign build output. ai
source-diff obfuscated-file:zmscore-uDFFyCiZ.d.mts AI (source-diff): Type declaration file, minified but readable; no obfuscation signature. ai
source-diff net-exec-file:chunk-Q4433MCT.mjs AI (source-diff): tsup-bundled client fetch logic; benign build output. ai
source-diff net-exec-file:zmscore-uDFFyCiZ.d.ts AI (source-diff): Type declaration file only, no runtime exec. ai
source-diff obfuscated-file:zmscore-uDFFyCiZ.d.ts AI (source-diff): Type declaration file, minified; benign. ai
source-diff net-exec-file:zmscore-uDFFyCiZ.d.mts AI (source-diff): Type declaration file only, no runtime exec. ai
source-diff net-exec-file:chunk-56TVFNIH.mjs AI (source-diff): tsup-bundled client output; no dropper behavior, atob is a polyfill. ai
source-diff net-exec-file:chunk-3XV7NWGI.mjs AI (source-diff): tsup-bundled HttpClient/dist output; benign for this bundled package. ai
source-diff obfuscated-file:zmscore-80635339.d.ts AI (source-diff): Large generated TypeScript declaration file, not obfuscation. ai
source-diff net-exec-file:chunk-DFUAPYBG.mjs AI (source-diff): esbuild-bundled client, same benign fetch-to-baseUrl pattern. ai
source-diff net-exec-file:zmscore-80635339.d.ts AI (source-diff): Type declaration file; no executable payload. ai
source-diff net-exec-file:chunk-4DQNQAF7.js AI (source-diff): tsup bundle; fetch targets user-supplied Upstash REST URL, no dynamic exec. ai
source-diff net-exec-file:chunk-FV6JMGNF.mjs AI (source-diff): tsup build output of the HTTP client; benign fetch-based REST client, not a dropper. ai
source-diff obfuscated-file:zmscore-Dc6Llqgr.d.ts AI (source-diff): Long lines are TS type declarations, not obfuscation. ai
source-diff net-exec-file:zmscore-Dc6Llqgr.d.ts AI (source-diff): Type-declaration file; no runtime exec. ai
source-diff obfuscated-file:zmscore-Dc6Llqgr.d.mts AI (source-diff): Long lines are TS type declarations, not obfuscation. ai
source-diff net-exec-file:zmscore-Dc6Llqgr.d.mts AI (source-diff): Type-declaration file; no runtime exec. ai
provenance publisher-changed AI (provenance): Known Upstash org maintainer transition; publisher has clean track record. ai
source-diff net-exec-file:chunk-JNBN5IB4.js AI (source-diff): tsup build output of official client; fetch is the REST transport, not a dropper. ai
source-diff net-exec-file:chunk-6D54FT2F.mjs AI (source-diff): tsup ESM bundle; fetch is the REST client transport. ai
source-diff net-exec-file:zmscore-BLgYk16R.d.mts AI (source-diff): Type declaration file, no runtime code. ai
source-diff obfuscated-file:zmscore-BLgYk16R.d.mts AI (source-diff): Minified type declaration; build artifact. ai
source-diff net-exec-file:zmscore-BLgYk16R.d.ts AI (source-diff): Type declaration file, no runtime code. ai
source-diff obfuscated-file:zmscore-BLgYk16R.d.ts AI (source-diff): Minified/long-line type declaration file; benign build artifact. ai
source-diff obfuscated-file:zmscore-C3G81zLz.d.ts AI (source-diff): tsup-generated .d.ts type-decl file; minified build output. ai
source-diff net-exec-file:chunk-T6D4KAGH.mjs AI (source-diff): tsup bundle of HTTP client; net calls to Upstash REST API are the package's function. ai
source-diff net-exec-file:zmscore-C3G81zLz.d.mts AI (source-diff): Type-declaration file, no executable code. ai
source-diff net-exec-file:zmscore-C3G81zLz.d.ts AI (source-diff): Type-declaration file, no executable code. ai
source-diff obfuscated-file:zmscore-C3G81zLz.d.mts AI (source-diff): tsup-generated .d.mts type-decl file; long lines are build output, not obfuscation. ai
source-diff net-exec-file:zmscore-490ca5bd.d.ts AI (source-diff): .d.ts types file; no runtime behavior. ai
source-diff obfuscated-file:zmscore-490ca5bd.d.ts AI (source-diff): Long-line TS type declaration file, not obfuscation. ai
source-diff net-exec-file:chunk-4AITRGZA.mjs AI (source-diff): ESM twin of same bundled client; benign fetch+base64 decode. ai
source-diff net-exec-file:chunk-6GSQ2Y4G.js AI (source-diff): tsup bundle; fetch to user's baseUrl, no dynamic code exec. ai
source-diff obfuscated-file:zmscore-BdNsMd17.d.mts AI (source-diff): Long-line .d.ts type declaration file, not obfuscation. ai
source-diff net-exec-file:chunk-NAQE7K3X.mjs AI (source-diff): tsup build bundle for the redis client; no net-exec payload, benign build output. ai
source-diff net-exec-file:zmscore-BdNsMd17.d.mts AI (source-diff): TypeScript declaration file, no executable payload. ai
source-diff obfuscated-file:zmscore-BdNsMd17.d.ts AI (source-diff): Long-line .d.ts type declaration file, not obfuscation. ai
source-diff net-exec-file:zmscore-BdNsMd17.d.ts AI (source-diff): TypeScript declaration file, no executable payload. ai
source-diff net-exec-file:chunk-ISIFYONA.js AI (source-diff): tsup-bundled REST client; fetch+base64 decode is core function, not exec-of-fetched-code. ai
source-diff net-exec-file:chunk-QHHA5Z3E.mjs AI (source-diff): Same bundled client as .js variant; benign fetch/atob. ai
source-diff net-exec-file:chunk-V7IBZRDB.mjs AI (source-diff): tsup-bundled REST client fetch; benign build output ai
source-diff net-exec-file:chunk-OOKBOKSO.js AI (source-diff): tsup-bundled REST client fetch; benign build output for this package ai
source-diff net-exec-file:chunk-2DN6UAHL.mjs AI (source-diff): tsup-bundled REST client; benign fetch+base64, not a dropper. ai
source-diff net-exec-file:zmscore-9faf292c.d.ts AI (source-diff): Type declaration file; no executable network/code path. ai
source-diff obfuscated-file:zmscore-9faf292c.d.ts AI (source-diff): Generated .d.ts type defs with long lines; minified, not obfuscated. ai
source-diff net-exec-file:chunk-C3VPBW4T.js AI (source-diff): tsup-bundled REST client; fetch targets user's Upstash baseUrl, no dynamic code exec. ai
source-diff net-exec-file:chunk-VQFAJYXK.mjs AI (source-diff): Same bundled fetch/base64 REST plumbing in ESM output. ai
source-diff net-exec-file:zmscore-22fd48c7.d.ts AI (source-diff): .d.ts type declarations, no executable code. ai
source-diff obfuscated-file:zmscore-22fd48c7.d.ts AI (source-diff): TypeScript declaration file with long type lines; not obfuscation. ai
source-diff net-exec-file:chunk-T2XXQHH4.js AI (source-diff): tsup-bundled REST client; fetch to configured Upstash baseUrl, no dynamic code exec. ai
source-diff net-exec-file:chunk-LE5YZT4V.mjs AI (source-diff): Same bundled HTTP client; benign fetch to configured endpoint. ai
source-diff net-exec-file:zmscore-d1ec861c.d.ts AI (source-diff): Bundled .d.ts types; no runtime behavior. ai
source-diff obfuscated-file:zmscore-d1ec861c.d.ts AI (source-diff): Type declaration file; long lines are minified .d.ts, not obfuscation. ai
source-diff net-exec-file:chunk-X3GXBTTA.js AI (source-diff): tsup bundle; fetch targets user-supplied Upstash baseUrl, no dynamic code exec. ai
source-diff net-exec-file:chunk-2X4SLXT7.mjs AI (source-diff): Bundled build artifact for HTTP-based Redis client; network+exec is core functionality. ai
source-diff net-exec-file:zmscore-BshEAkn7.d.ts AI (source-diff): Type declaration file; no executable code. False positive. ai
source-diff net-exec-file:zmscore-BshEAkn7.d.mts AI (source-diff): Type declaration file; no executable code. False positive. ai
source-diff obfuscated-file:zmscore-BshEAkn7.d.mts AI (source-diff): Bundled TypeScript declaration file with long type-union lines; not obfuscation. ai
source-diff obfuscated-file:zmscore-BshEAkn7.d.ts AI (source-diff): Bundled TypeScript declaration file with long type-union lines; not obfuscation. ai
source-diff net-exec-file:chunk-AIBLSL5D.mjs AI (source-diff): Bundled Redis HTTP client; network+exec is core functionality. ai
source-diff net-exec-file:chunk-JXBYIALB.mjs AI (source-diff): Bundled Redis client source; network calls are core functionality. ai
source-diff net-exec-file:chunk-CXQK4IKU.mjs AI (source-diff): Bundled SDK entry point with HTTP client logic; expected for a Redis HTTP client. ai
source-diff net-exec-file:zmscore-DzNHSWxc.d.ts AI (source-diff): Type declarations only; no executable code. ai
source-diff obfuscated-file:zmscore-DzNHSWxc.d.ts AI (source-diff): TypeScript declaration file with long type-union lines, not obfuscation. ai
source-diff obfuscated-file:zmscore-DzNHSWxc.d.mts AI (source-diff): TypeScript declaration file with long type-union lines, not obfuscation. ai
source-diff net-exec-file:zmscore-DzNHSWxc.d.mts AI (source-diff): Type declarations only; no executable code. ai
source-diff net-exec-file:chunk-QZ3IMTW7.mjs AI (source-diff): Bundled Redis client code; network calls are the product's core function. ai
source-diff net-exec-file:zmscore-Cq_Bzgy4.d.mts AI (source-diff): Type declarations only; no executable code. ai
source-diff net-exec-file:chunk-TAJI6TAE.mjs AI (source-diff): Bundled SDK module with HTTP client logic; expected for a Redis HTTP client. ai
source-diff net-exec-file:zmscore-Cq_Bzgy4.d.ts AI (source-diff): Type declarations only; no executable code. ai
source-diff obfuscated-file:zmscore-Cq_Bzgy4.d.ts AI (source-diff): TypeScript declaration bundle with long type-union lines; not obfuscated. ai
source-diff obfuscated-file:zmscore-Cq_Bzgy4.d.mts AI (source-diff): TypeScript declaration bundle with long type-union lines; not obfuscated. ai
source-diff net-exec-file:chunk-XJQAWEWD.mjs AI (source-diff): Standard bundled Redis client code; network calls are the product's purpose. ai
source-diff net-exec-file:zmscore-DWj9Vh1g.d.ts AI (source-diff): Type declaration file; no executable code. ai
source-diff net-exec-file:zmscore-DWj9Vh1g.d.mts AI (source-diff): Type declaration file; no executable code. ai
source-diff obfuscated-file:zmscore-DWj9Vh1g.d.ts AI (source-diff): TypeScript declaration file with long type-union lines; not obfuscated code. ai
source-diff obfuscated-file:zmscore-DWj9Vh1g.d.mts AI (source-diff): TypeScript declaration file with long type-union lines; not obfuscated code. ai
source-diff net-exec-file:chunk-2BA3VA6P.mjs AI (source-diff): Bundled Redis client with fetch calls; expected for this HTTP-based Redis SDK. ai
source-diff net-exec-file:zmscore-CgRD7oFR.d.ts AI (source-diff): Type declaration file; no executable code. ai
source-diff net-exec-file:zmscore-CgRD7oFR.d.mts AI (source-diff): Type declaration file; no executable code. ai
source-diff obfuscated-file:zmscore-CgRD7oFR.d.ts AI (source-diff): TypeScript .d.ts declaration file with long type lines, not obfuscation. ai
source-diff obfuscated-file:zmscore-CgRD7oFR.d.mts AI (source-diff): TypeScript .d.mts declaration file with long type lines, not obfuscation. ai
source-diff obfuscated-file:zmscore-Dq2s28SC.d.ts AI (source-diff): Bundled TypeScript declaration file with long type definition lines; not obfuscated. .d.ts files are inert type declarations. ai
source-diff net-exec-file:chunk-MBZJLX7T.mjs AI (source-diff): Bundled Redis client code; network calls + dynamic patterns are inherent to an HTTP-based Redis client built with tsup. ai
source-diff net-exec-file:zmscore-Dq2s28SC.d.ts AI (source-diff): TypeScript declaration file (.d.ts) — cannot execute code. False positive from type signatures mentioning network-related types. ai
source-diff net-exec-file:zmscore-Dq2s28SC.d.mts AI (source-diff): TypeScript declaration file (.d.mts) — cannot execute code. False positive from type signatures mentioning network-related types. ai
source-diff obfuscated-file:zmscore-Dq2s28SC.d.mts AI (source-diff): Bundled TypeScript declaration file with long type definition lines; not obfuscated. .d.mts files are inert type declarations. ai
semgrep semgrep:base64-decode AI (semgrep): The base64 decode is a standard atob() polyfill for Node.js environments. No malicious payload; this is a well-known compatibility pattern stable across versions. ai
typosquat typosquat.levenshtein:redux AI (typosquat): @upstash/redis is a legitimate, scoped Upstash package with 1646 days of history and 2.3M weekly downloads. Levenshtein match to 'redux' is a false positive with no brand or purpose overlap. ai

Versions (showing 94 of 94)

Version Deps Published
1.38.0 1 / 3
1.37.0 1 / 3
1.36.4 1 / 12
1.36.3 1 / 12
1.36.2 1 / 12
1.36.1 1 / 12
1.36.0 1 / 12
1.35.8 1 / 12
1.35.7 1 / 12
1.35.6 1 / 12
1.35.5 1 / 12
1.35.4 1 / 12
1.35.3 1 / 12
1.35.2 1 / 12
1.35.1 1 / 12
1.35.0 1 / 12
1.34.9 1 / 13
1.34.8 1 / 13
1.34.7 1 / 13
1.34.6 1 / 13
1.34.5 1 / 13
1.34.4 1 / 13
1.34.3 1 / 13
1.34.2 1 / 13
1.34.1 1 / 13
1.34.0 1 / 13
1.33.0 1 / 6
1.32.0 1 / 6
1.31.6 1 / 6
1.31.5 1 / 6
1.31.4 1 / 6
1.31.3 1 / 6
1.31.2 1 / 6
1.31.1 1 / 6
1.31.0 1 / 6
1.30.1 1 / 6
1.30.0 1 / 6
1.29.0 1 / 6
1.27.1 1 / 4
1.25.2 1 / 4
1.25.1 1 / 4
1.25.0 1 / 4
1.24.2 2 / 3
1.24.1 2 / 3
1.24.0 2 / 3
1.23.4 1 / 0
1.23.3 1 / 0
1.23.2 1 / 0
1.23.1 1 / 0
1.22.1 1 / 0
1.22.0 1 / 0
1.21.0 1 / 0
1.20.6 1 / 0
1.20.5 1 / 0
1.20.4 1 / 0
1.20.3 1 / 0
1.20.2 1 / 0
1.20.1 1 / 0
1.20.0 1 / 0
1.19.3 1 / 0
1.19.2 1 / 0
1.19.1 1 / 0
1.19.0 1 / 0
1.18.5 1 / 0
1.18.4 1 / 0
1.18.3 1 / 0
1.18.2 1 / 0
1.18.1 1 / 0
1.18.0 1 / 0
1.17.0 1 / 0
1.16.1 1 / 0
1.16.0 1 / 0
1.15.1 1 / 0
1.15.0 1 / 0
1.13.1 1 / 0
1.11.0 1 / 2
1.10.1 1 / 2
1.10.0 1 / 2
1.8.0 1 / 2
1.6.1 1 / 2
1.6.0 1 / 2
1.5.0 1 / 2
1.4.0 1 / 2
1.3.5 2 / 2
1.3.4 2 / 2
1.3.3 2 / 2
1.3.1 1 / 11
1.3.0 1 / 11
1.2.0 1 / 17
1.1.0 1 / 17
1.0.3 1 / 17
1.0.2 1 / 17
1.0.1 1 / 17
1.0.0 1 / 17

v1.34.8

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2025-04-15) provenance

This version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-5XANP4AV.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-CjoCv9kz.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-CjoCv9kz.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-CjoCv9kz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-CjoCv9kz.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.7

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2025-04-07) provenance

This version was published by a different npm account than previous versions on 2025-04-07. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-TA73MYTP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-hRk-rDLY.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-hRk-rDLY.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-hRk-rDLY.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-hRk-rDLY.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.6

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2025-03-21) provenance

This version was published by a different npm account than previous versions on 2025-03-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-56TVFNIH.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BdNsMd17.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BdNsMd17.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BdNsMd17.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BdNsMd17.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.5

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2025-03-06) provenance

This version was published by a different npm account than previous versions on 2025-03-06. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-NAQE7K3X.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BdNsMd17.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BdNsMd17.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BdNsMd17.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BdNsMd17.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.4

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2025-02-04) provenance

This version was published by a different npm account than previous versions on 2025-02-04. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-T6D4KAGH.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-C3G81zLz.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-C3G81zLz.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-C3G81zLz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-C3G81zLz.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.3

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2024-10-09) provenance

This version was published by a different npm account than previous versions on 2024-10-09. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-FV6JMGNF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-Dc6Llqgr.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-Dc6Llqgr.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-Dc6Llqgr.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-Dc6Llqgr.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.2

7 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2024-10-04) provenance

This version was published by a different npm account than previous versions on 2024-10-04. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-3XV7NWGI.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BLgYk16R.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BLgYk16R.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BLgYk16R.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BLgYk16R.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.1

8 findings
HIGH Publisher changed: hezarfen → cahidarda (on 2024-09-30) provenance

This version was published by a different npm account than previous versions on 2024-09-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: chunk-JNBN5IB4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-6D54FT2F.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BLgYk16R.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BLgYk16R.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-BLgYk16R.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-BLgYk16R.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.34.0

7 findings
HIGH New file with network + code execution: chunk-JPMD56E6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-Q4433MCT.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-uDFFyCiZ.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-uDFFyCiZ.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-uDFFyCiZ.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-uDFFyCiZ.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.33.0

5 findings
HIGH New file with network + code execution: chunk-5IGN7AOR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-7NCPWARK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-80635339.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-80635339.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.32.0

5 findings
HIGH New file with network + code execution: chunk-4DQNQAF7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-DFUAPYBG.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-80635339.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-80635339.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.6

5 findings
HIGH New file with network + code execution: chunk-C3VPBW4T.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-2DN6UAHL.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-9faf292c.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-9faf292c.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.5

5 findings
HIGH New file with network + code execution: chunk-ISIFYONA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-QHHA5Z3E.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-9faf292c.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-9faf292c.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.4

5 findings
HIGH New file with network + code execution: chunk-6GSQ2Y4G.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-4AITRGZA.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-490ca5bd.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-490ca5bd.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.3

5 findings
HIGH New file with network + code execution: chunk-T2XXQHH4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-VQFAJYXK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-22fd48c7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-22fd48c7.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.2

5 findings
HIGH New file with network + code execution: chunk-OOKBOKSO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-V7IBZRDB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-22fd48c7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-22fd48c7.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.1

5 findings
HIGH New file with network + code execution: chunk-X3GXBTTA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-LE5YZT4V.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: zmscore-d1ec861c.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-d1ec861c.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.31.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.30.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.30.0

12 findings
HIGH New file with network + code execution: chunk-DKKYFKP2.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-OHFT7Y75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-4382faf4.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-4382faf4.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2024-04-18, unremoved on npm for 823d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2024-04-18. It has since remained available on npm for 823 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.29.0

12 findings
HIGH New file with network + code execution: chunk-W3IXR5IB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-WDEZBVJF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-07021e27.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-07021e27.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2024-03-22, unremoved on npm for 850d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2024-03-22. It has since remained available on npm for 850 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.1

12 findings
HIGH New file with network + code execution: chunk-ITYCTRXG.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-KXHOP7IA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-fa7fc9c8.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-fa7fc9c8.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-12-19, unremoved on npm for 944d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-12-19. It has since remained available on npm for 944 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.25.2

12 findings
HIGH New file with network + code execution: chunk-5HXMXPOL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-E24372TH.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-415f6c9f.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-415f6c9f.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-12-13, unremoved on npm for 950d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-12-13. It has since remained available on npm for 950 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.25.1

12 findings
HIGH New file with network + code execution: chunk-I6BAFAQP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-SMBYCQIJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-b6b93f14.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-b6b93f14.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-11-10, unremoved on npm for 983d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-11-10. It has since remained available on npm for 983 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.25.0

12 findings
HIGH New file with network + code execution: chunk-NSLIVMRY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: chunk-WAPWYB6L.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-b6b93f14.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-b6b93f14.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-11-09, unremoved on npm for 984d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-11-09. It has since remained available on npm for 984 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.2

22 findings
HIGH New obfuscated file: cloudflare.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: fastly.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: nodejs.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: zmscore-10fd3773.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: zmscore-10fd3773.d.ts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Modified file became obfuscated: cloudflare.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: cloudflare.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: cloudflare.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: fastly.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.d.ts source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file became obfuscated: nodejs.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-10-30, unremoved on npm for 994d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-10-30. It has since remained available on npm for 994 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.1

14 findings
HIGH Modified file became obfuscated: cloudflare.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: cloudflare.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-10-27, unremoved on npm for 997d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-10-27. It has since remained available on npm for 997 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.0

14 findings
HIGH Modified file became obfuscated: cloudflare.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: cloudflare.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: cloudflare.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: fastly.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: fastly.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

HIGH Modified file became obfuscated: nodejs.mjs source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

HIGH Modified file gained network + code execution: nodejs.mjs source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

MEDIUM Publisher changed: mdogan → hezarfen (on 2023-10-26, unremoved on npm for 998d) provenance

This version was published by a different npm account (hezarfen) than the most recent previously approved version (mdogan) on 2023-10-26. It has since remained available on npm for 998 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.4

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-10-17, unremoved on npm for 1007d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-10-17. It has since remained available on npm for 1007 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.3

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-10-10, unremoved on npm for 1014d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-10-10. It has since remained available on npm for 1014 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.2

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-10-10, unremoved on npm for 1014d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-10-10. It has since remained available on npm for 1014 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-10-10, unremoved on npm for 1014d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-10-10. It has since remained available on npm for 1014 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-09-29, unremoved on npm for 1025d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-09-29. It has since remained available on npm for 1025 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-06-28, unremoved on npm for 1118d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-06-28. It has since remained available on npm for 1118 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-05-31, unremoved on npm for 1146d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-05-31. It has since remained available on npm for 1146 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.6

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-05-04, unremoved on npm for 1173d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-05-04. It has since remained available on npm for 1173 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.5

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-05-02, unremoved on npm for 1175d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-05-02. It has since remained available on npm for 1175 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.4

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-04-18, unremoved on npm for 1189d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-04-18. It has since remained available on npm for 1189 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.3

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-04-14, unremoved on npm for 1193d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-04-14. It has since remained available on npm for 1193 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.2

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-03-29, unremoved on npm for 1209d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-03-29. It has since remained available on npm for 1209 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-02-27, unremoved on npm for 1239d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-02-27. It has since remained available on npm for 1239 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-02-08, unremoved on npm for 1258d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-02-08. It has since remained available on npm for 1258 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.3

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-01-19, unremoved on npm for 1278d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-01-19. It has since remained available on npm for 1278 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.2

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-01-19, unremoved on npm for 1278d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-01-19. It has since remained available on npm for 1278 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-01-07, unremoved on npm for 1290d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-01-07. It has since remained available on npm for 1290 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-01-07, unremoved on npm for 1290d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-01-07. It has since remained available on npm for 1290 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.5

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2023-01-02, unremoved on npm for 1295d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2023-01-02. It has since remained available on npm for 1295 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.4

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-12-19, unremoved on npm for 1309d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-12-19. It has since remained available on npm for 1309 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.3

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-12-19, unremoved on npm for 1309d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-12-19. It has since remained available on npm for 1309 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.2

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-12-19, unremoved on npm for 1309d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-12-19. It has since remained available on npm for 1309 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-11-26, unremoved on npm for 1332d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-11-26. It has since remained available on npm for 1332 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.18.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-11-24, unremoved on npm for 1334d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-11-24. It has since remained available on npm for 1334 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-11-23, unremoved on npm for 1335d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-11-23. It has since remained available on npm for 1335 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-11-16, unremoved on npm for 1342d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-11-16. It has since remained available on npm for 1342 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-10-31, unremoved on npm for 1358d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-10-31. It has since remained available on npm for 1358 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-10-26, unremoved on npm for 1363d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-10-26. It has since remained available on npm for 1363 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-10-13, unremoved on npm for 1376d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-10-13. It has since remained available on npm for 1376 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-09-03, unremoved on npm for 1416d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-09-03. It has since remained available on npm for 1416 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-08-03, unremoved on npm for 1447d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-08-03. It has since remained available on npm for 1447 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-07-19, unremoved on npm for 1462d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-07-19. It has since remained available on npm for 1462 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-07-19, unremoved on npm for 1462d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-07-19. It has since remained available on npm for 1462 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-07-12, unremoved on npm for 1469d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-07-12. It has since remained available on npm for 1469 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-06-01, unremoved on npm for 1510d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-06-01. It has since remained available on npm for 1510 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-05-30, unremoved on npm for 1512d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-05-30. It has since remained available on npm for 1512 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-05-30, unremoved on npm for 1512d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-05-30. It has since remained available on npm for 1512 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

2 findings
MEDIUM Publisher changed: mdogan → chronark (on 2022-05-23, unremoved on npm for 1519d) provenance

This version was published by a different npm account (chronark) than the most recent previously approved version (mdogan) on 2022-05-23. It has since remained available on npm for 1519 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.