← Home

@vitessce/image-utils

44
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/index-c873a642.js AI (source-diff): Bundled build artifact for image utils lib; no exfil destination evident, pattern-match false positive. ai
source-diff obfuscated-file:dist/index-c873a642.js AI (source-diff): Vite/rollup bundle output, not obfuscation; long lines are minification. ai
source-diff obfuscated-file:dist/index-ViwbUL2_.js AI (source-diff): Vite-bundled output (lodash/react libs), not true obfuscation. ai
source-diff obfuscated-file:dist/lerc-D25tZF7s.js AI (source-diff): Bundled Esri lerc decoder lib, minified not obfuscated. ai
source-diff net-exec-file:dist/index-ViwbUL2_.js AI (source-diff): Bundled build artifact; no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/lerc-DSITWi_1.js AI (source-diff): Bundled third-party Lerc/Esri decoder, standard minified vendored code. ai
source-diff obfuscated-file:dist/index-CGeOpq7J.js AI (source-diff): Bundled Vite output (lodash/viv deps), not true obfuscation. ai
source-diff net-exec-file:dist/index-CGeOpq7J.js AI (source-diff): False positive: bundled library code, no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/lerc-BvsBT0NB.js AI (source-diff): Bundled Esri lerc decoder library, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-CtJlyOO6.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/index-CtJlyOO6.js AI (source-diff): Bundled lib code (lodash-style helpers), no real network+exec malware pattern. ai
source-diff obfuscated-file:dist/index-15b29b74.js AI (source-diff): Vite/rollup bundle output, not true obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party @vitessce/globals sibling at same version. ai
source-diff net-exec-file:dist/index-15b29b74.js AI (source-diff): Bundled viv/lodash deps naturally contain fetch+eval-like patterns; no concrete malicious behavior found. ai
source-diff obfuscated-file:dist/index-93bb5c05.js AI (source-diff): Vite/Rollup bundle output, not true obfuscation; large monorepo package. ai
source-diff net-exec-file:dist/index-93bb5c05.js AI (source-diff): Generic bundled deps trigger net+exec heuristic; no concrete malicious behavior found. ai
source-diff obfuscated-file:dist/index-f9f51d7d.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/index-f9f51d7d.js AI (source-diff): Bundled build artifact; no evidence of dropper/loader behavior. ai
source-diff net-exec-file:dist/index-8b6c9313.js AI (source-diff): Bundled imaging/viv deps naturally include fetch+eval-like patterns; no malicious destination found. ai
source-diff obfuscated-file:dist/index-8b6c9313.js AI (source-diff): Bundled build output (esbuild banner + lodash internals), not obfuscation. ai
source-diff net-exec-file:dist/index-ef4f2fce.js AI (source-diff): Bundled imaging library code (viv/lerc); no concrete malicious destination shown. ai
source-diff obfuscated-file:dist/index-ef4f2fce.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; consistent with package's build pipeline. ai
source-diff net-exec-file:dist/index-e10282cc.js AI (source-diff): Bundled build artifact of viewer lib deps, no concrete malicious network behavior. ai
source-diff obfuscated-file:dist/index-e10282cc.js AI (source-diff): Bundled/minified vite output, not true obfuscation; large legit library chunk. ai
npm-metadata no-description AI (npm-metadata): Scoped package in established ecosystem; missing description is metadata-only, not a malware indicator. ai
dependencies unvetted-dep:@vitessce/utils AI (dependencies): First-party vitessce monorepo package; stable sibling dependency. ai
dependencies unvetted-dep:@vitessce/spatial-utils AI (dependencies): First-party vitessce monorepo package; stable sibling dependency. ai
dependencies unvetted-dep:@hms-dbmi/viv AI (dependencies): Known imaging library from the same HMS lab that maintains vitessce; stable dependency across versions. ai

Versions (showing 44 of 44)

Version Deps Published
4.0.1 5 / 2
4.0.0 5 / 2
3.9.11 5 / 2
3.9.10 5 / 2
3.9.9 5 / 2
3.9.8 5 / 2
3.9.7 5 / 2
3.9.6 5 / 2
3.9.5 5 / 2
3.9.4 5 / 2
3.9.3 5 / 2
3.9.2 5 / 2
3.9.1 5 / 2
3.9.0 5 / 2
3.8.13 5 / 2
3.8.10 5 / 2
3.8.9 5 / 2
3.8.8 5 / 2
3.8.7 5 / 2
3.8.6 5 / 2
3.5.9 5 / 2
3.5.8 5 / 2
3.5.7 5 / 2
3.5.6 4 / 2
3.5.5 4 / 2
3.5.4 4 / 2
3.5.3 4 / 2
3.5.2 4 / 2
3.5.1 4 / 2
3.5.0 4 / 2
3.4.14 4 / 2
3.4.12 4 / 2
3.4.11 4 / 2
3.4.10 4 / 2
3.4.9 4 / 2
3.4.8 4 / 2
3.4.7 4 / 2
3.4.6 4 / 2
3.4.5 4 / 2
3.4.4 4 / 2
3.4.3 4 / 2
3.4.2 4 / 2
3.4.1 4 / 2
3.4.0 4 / 2

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

4 findings
HIGH New obfuscated file: dist/index-ViwbUL2_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ViwbUL2_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-D25tZF7s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.6

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.5

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.4

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.3

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.2

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.1

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.0

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.13

5 findings
HIGH New obfuscated file: dist/index-CGeOpq7J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CGeOpq7J.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DSITWi_1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2025-12-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2025-12-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.10

4 findings
HIGH New obfuscated file: dist/index-CtJlyOO6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CtJlyOO6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BvsBT0NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.9

4 findings
HIGH New obfuscated file: dist/index-CtJlyOO6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CtJlyOO6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BvsBT0NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.8

4 findings
HIGH New obfuscated file: dist/index-CtJlyOO6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CtJlyOO6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BvsBT0NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.7

4 findings
HIGH New obfuscated file: dist/index-CtJlyOO6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CtJlyOO6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BvsBT0NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.6

4 findings
HIGH New obfuscated file: dist/index-CtJlyOO6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CtJlyOO6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BvsBT0NB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.9

3 findings
HIGH New obfuscated file: dist/index-15b29b74.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-15b29b74.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.8

3 findings
HIGH New obfuscated file: dist/index-15b29b74.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-15b29b74.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.7

3 findings
HIGH New obfuscated file: dist/index-e10282cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-e10282cc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.6

3 findings
HIGH New obfuscated file: dist/index-93bb5c05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-93bb5c05.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.5

3 findings
HIGH New obfuscated file: dist/index-93bb5c05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-93bb5c05.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.4

3 findings
HIGH New obfuscated file: dist/index-93bb5c05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-93bb5c05.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.3

3 findings
HIGH New obfuscated file: dist/index-93bb5c05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-93bb5c05.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.2

3 findings
HIGH New obfuscated file: dist/index-f9f51d7d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-f9f51d7d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.1

3 findings
HIGH New obfuscated file: dist/index-f9f51d7d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-f9f51d7d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

3 findings
HIGH New obfuscated file: dist/index-c873a642.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-c873a642.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.14

3 findings
HIGH New obfuscated file: dist/index-8b6c9313.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-8b6c9313.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.12

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.11

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.10

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.9

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.8

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.7

3 findings
HIGH New obfuscated file: dist/index-ef4f2fce.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-ef4f2fce.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.