← Home

@uxland/primary-shell

Primaria Shell

47
Versions
UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

uxland-admindanielcabiscol

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/index-DrGDmXh2.js AI (source-diff): Bundled frontend app code (React/vite), no evidence of loader/dropper behavior. ai
source-diff obfuscated-file:dist/index-DrGDmXh2.js AI (source-diff): Vite/rollup bundle output, not true obfuscation; long lines are minification. ai
source-diff net-exec-file:dist/index--RrXhs-S.js AI (source-diff): Standard bundled front-end code (react/vite), no concrete malicious behavior found. ai
source-diff obfuscated-file:dist/index--RrXhs-S.js AI (source-diff): Bundled Vite/Rollup build output, not obfuscation; long-established publisher. ai
source-diff obfuscated-file:dist/index-DCORE1l4.js AI (source-diff): Vite/Rollup bundle output, not true obfuscation; standard minified vendor code. ai
source-diff net-exec-file:dist/index-DCORE1l4.js AI (source-diff): Bundled polyfills/build output; no concrete malicious network+exec behavior shown. ai
source-diff net-exec-file:dist/index-s4j8zpRH.js AI (source-diff): Bundled app code (React/polyfills), no evidence of fetched/executed payload. ai
source-diff obfuscated-file:dist/index-s4j8zpRH.js AI (source-diff): Vite/rollup bundle with license banners and readable imports; minified, not obfuscated. ai
source-diff net-exec-file:dist/index-DD62MwFV.js AI (source-diff): Bundler artifact; no dropper/loader behavior observed in sample. ai
source-diff obfuscated-file:dist/index-DD62MwFV.js AI (source-diff): Bundled Vite output (react/tslib/Reflect), not true obfuscation. ai
source-diff net-exec-file:dist/index-B9r6-Xmj.js AI (source-diff): Network+exec pattern in a React app bundle is expected; no hostile destination or dropper behavior visible. ai
source-diff obfuscated-file:dist/index-B9r6-Xmj.js AI (source-diff): Vite-bundled output; long lines are minified bundle, not obfuscation. Stable pattern for this package. ai
source-diff net-exec-file:dist/index-BiktcB77.js AI (source-diff): Network calls and dynamic code in bundled React app shell are expected; no hostile destination or dropper behavior evident. ai
source-diff obfuscated-file:dist/index-BiktcB77.js AI (source-diff): Vite bundle output; long lines are minified build artifacts, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-CULx5ubY.js AI (source-diff): Vite-bundled output; long lines are minification, not obfuscation. Stable pattern for this package. ai
source-diff net-exec-file:dist/index-CULx5ubY.js AI (source-diff): Network+exec pattern in a bundled React app shell is expected; no concrete malicious behavior present. ai
source-diff net-exec-file:dist/index-D-GssSmM.js AI (source-diff): Network calls and dynamic code (new Function) are part of the app's documented broker/event factory pattern in a React shell bundle. ai
source-diff obfuscated-file:dist/index-D-GssSmM.js AI (source-diff): Standard Vite-bundled minified output; long lines are expected in bundled JS for this package. ai
source-diff net-exec-file:dist/index-DyeUdeNy.js AI (source-diff): Network calls and dynamic code (new Function) are part of the React/reflect-metadata bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-DyeUdeNy.js AI (source-diff): Vite-bundled output; long lines are minified bundle, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-BUnSpNVB.js AI (source-diff): Vite-generated bundle with hashed filename; minification is expected for this build toolchain. ai
source-diff net-exec-file:dist/index-BUnSpNVB.js AI (source-diff): Network calls and dynamic code (new Function) are part of the app's documented event-class factory and React runtime, not dropper behavior. ai
source-diff net-exec-file:dist/index-DasFWYhc.js AI (source-diff): Network calls and dynamic code (new Function) are part of the React shell bundle and event factory; not dropper behavior. ai
source-diff obfuscated-file:dist/index-DasFWYhc.js AI (source-diff): Standard Vite-bundled minified output; long lines are expected in bundled dist files for this package. ai
source-diff net-exec-file:dist/index-8_KLfK7r.js AI (source-diff): Network calls and dynamic code in a React app bundle are expected; no dropper pattern in sample. ai
source-diff obfuscated-file:dist/index-8_KLfK7r.js AI (source-diff): Standard Vite-minified bundle with source map; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-B0BnyHR2.js AI (source-diff): Vite-bundled minified output; long lines are standard bundle artifact, not obfuscation. ai
source-diff net-exec-file:dist/index-B0BnyHR2.js AI (source-diff): Network calls and dynamic code in a React app bundle are expected; no dropper pattern in sample. ai
source-diff net-exec-file:dist/index-HxUANPyC.js AI (source-diff): Network calls and dynamic code in bundled frontend app are expected; no dropper pattern in sample. ai
source-diff obfuscated-file:dist/index-HxUANPyC.js AI (source-diff): Standard Vite bundle output; sample shows legitimate React/reflect-metadata code, not obfuscation. ai
source-diff net-exec-file:dist/index-CW9SRbzE.js AI (source-diff): Network calls and dynamic code (new Function) are part of normal React/inversify bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-CW9SRbzE.js AI (source-diff): Standard Vite build output; minified bundle is expected for this package. ai
source-diff net-exec-file:dist/index-B7XP7G0f.js AI (source-diff): Network calls and new Function() are part of the React shell app bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-B7XP7G0f.js AI (source-diff): Standard Vite bundle output; long lines are minified but not obfuscated — readable source map included. ai
source-diff net-exec-file:dist/index-DSWQpDr0.js AI (source-diff): Bundled SPA shell; network calls and Function() globalThis polyfill are expected in dist output. ai
source-diff obfuscated-file:dist/index-DSWQpDr0.js AI (source-diff): Vite bundle output with source map; minified but not obfuscated. Stable pattern for this package. ai
source-diff net-exec-file:dist/index-CNpXjSPp.js AI (source-diff): Bundle includes reflect-metadata polyfill (Function constructor) and React app network calls; not malicious. ai
source-diff obfuscated-file:dist/index-CNpXjSPp.js AI (source-diff): Vite build bundle; minified output is expected for this package's dist folder. ai
source-diff obfuscated-file:dist/index-CsqWoBVE.js AI (source-diff): Standard Vite-bundled minified output for a React shell app; not obfuscation. ai
source-diff net-exec-file:dist/index-CsqWoBVE.js AI (source-diff): Network calls and dynamic code (new Function) are part of the app bundle's normal operation, not dropper behavior. ai
source-diff net-exec-file:dist/index-BPXzFbQm.js AI (source-diff): Network calls and dynamic code (new Function for event class creation) are part of the app's documented broker pattern, not dropper behavior. ai
source-diff obfuscated-file:dist/index-BPXzFbQm.js AI (source-diff): Vite-bundled frontend shell; minified dist output with accompanying source map is expected for this package. ai
source-diff net-exec-file:dist/index-0V-xXwce.js AI (source-diff): Network calls and dynamic code (new Function for event class factory) are part of the documented shell app bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-0V-xXwce.js AI (source-diff): Vite-bundled React/Lit shell app; minified dist output is expected and accompanied by a source map. ai
source-diff net-exec-file:dist/index-mgf5fUfq.js AI (source-diff): Network calls and dynamic code (new Function) are part of React/reflect-metadata bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/index-mgf5fUfq.js AI (source-diff): Vite-bundled frontend dist file; long lines are minified bundle output, not obfuscation. ai
source-diff net-exec-file:dist/index-Dnyofefj.js AI (source-diff): Network+exec pattern in a bundled shell app is expected; no dropper behavior in sample. ai
source-diff obfuscated-file:dist/index-Dnyofefj.js AI (source-diff): Large Vite bundle output; sample shows standard minified React code, not obfuscation. ai
source-diff obfuscated-file:dist/index-Z7V9O2zV.js AI (source-diff): Vite-bundled React app output; minified lines are expected build artifacts, not obfuscation. ai
source-diff net-exec-file:dist/index-Z7V9O2zV.js AI (source-diff): Network calls and dynamic code (new Function) are part of the bundled app runtime, not dropper behavior. ai
source-diff net-exec-file:dist/index-td5IxyX5.js AI (source-diff): Bundle includes reflect-metadata's Function() and axios; expected for this app shell. ai
source-diff obfuscated-file:dist/index-td5IxyX5.js AI (source-diff): Vite-bundled minified output with source map; not obfuscation. ai
source-diff obfuscated-file:dist/index-BPEC-whC.js AI (source-diff): Standard Vite bundle output; long lines are minified but not obfuscated — readable source and .map file both present. ai
source-diff net-exec-file:dist/index-BPEC-whC.js AI (source-diff): Network calls and dynamic code (new Function) are part of the app's event-class factory and React runtime, not dropper behavior. ai
source-diff obfuscated-file:dist/index-kl9Zgtus.js AI (source-diff): Standard Vite-bundled output; sample shows readable React/reflect-metadata code, not obfuscation. ai
source-diff net-exec-file:dist/index-kl9Zgtus.js AI (source-diff): Network calls and dynamic code in a frontend shell bundle are expected; no dropper pattern in sample. ai
source-diff net-exec-file:dist/index-ayzo4OJo.js AI (source-diff): Network calls and dynamic code in a React frontend bundle are normal; no dropper pattern in the sample. ai
source-diff obfuscated-file:dist/index-ayzo4OJo.js AI (source-diff): Standard Vite-minified React bundle; long lines are expected in bundled output, not obfuscation. ai
source-diff net-exec-file:dist/index-CXxEmHmi.js AI (source-diff): Network calls and dynamic code (new Function) are part of the bundled React app and event factory pattern, not dropper behavior. ai
source-diff obfuscated-file:dist/index-CXxEmHmi.js AI (source-diff): Vite-bundled frontend shell; large minified dist files are expected for this package. ai
source-diff net-exec-file:dist/index-B9gGnkza.js AI (source-diff): Network calls and dynamic code (new Function) are part of the bundled app framework, not dropper behavior. ai
source-diff obfuscated-file:dist/index-B9gGnkza.js AI (source-diff): Standard Vite bundle output; minified lines are expected for this build-tool-based package. ai
source-diff net-exec-file:dist/index-DHrGHdzq.js AI (source-diff): Network calls and dynamic code (new Function) are part of the app shell's documented event-class factory; no dropper pattern. ai
source-diff obfuscated-file:dist/index-DHrGHdzq.js AI (source-diff): Vite-bundled frontend output; minification is expected for this package's dist artifacts. ai
bogus-package bogus-package AI (bogus-package): Internal/private shell app; sparse README and no keywords are expected for org-internal packages. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used to dynamically create named event classes from controlled event name strings; not arbitrary user input. ai

Versions (showing 47 of 47)

Version Deps Published
7.45.9 2 / 20
7.45.8 2 / 20
7.45.7 2 / 20
7.45.6 2 / 20
7.45.5 2 / 20
7.45.4 2 / 20
7.45.3 2 / 20
7.45.2 2 / 20
7.45.1 2 / 20
7.45.0 2 / 20
7.44.3 2 / 20
7.44.2 2 / 20
7.44.1 2 / 20
7.43.5 2 / 20
7.43.4 2 / 20
7.43.3 2 / 20
7.43.2 2 / 20
7.43.1 2 / 20
7.43.0 2 / 20
7.42.0 2 / 20
7.41.8 2 / 20
7.41.7 2 / 20
7.41.6 2 / 20
7.41.5 2 / 20
7.41.4 2 / 20
7.41.3 2 / 20
7.41.2 2 / 20
7.41.1 2 / 20
7.41.0 2 / 20
7.40.4 2 / 20
7.40.3 2 / 20
7.40.2 2 / 20
7.40.1 2 / 20
7.40.0 2 / 20
7.39.0 2 / 20
7.38.5 2 / 20
7.38.4 2 / 20
7.38.3 2 / 20
7.38.2 2 / 20
7.38.1 2 / 20
7.38.0 2 / 20
7.37.2 2 / 20
7.37.1 2 / 20
7.37.0 2 / 20
7.36.5 2 / 20
7.18.0 2 / 20
7.17.0 2 / 20

v7.45.9

3 findings
HIGH New obfuscated file: dist/index-DrGDmXh2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DrGDmXh2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.8

3 findings
HIGH New obfuscated file: dist/index--RrXhs-S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index--RrXhs-S.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.7

3 findings
HIGH New obfuscated file: dist/index-DD62MwFV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DD62MwFV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.6

3 findings
HIGH New obfuscated file: dist/index-s4j8zpRH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-s4j8zpRH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.5

3 findings
HIGH New obfuscated file: dist/index-DCORE1l4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-DCORE1l4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.4

3 findings
HIGH New obfuscated file: dist/index-B9r6-Xmj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B9r6-Xmj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.45.3

3 findings
HIGH New obfuscated file: dist/index-B9r6-Xmj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B9r6-Xmj.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v7.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.