← Home

@voiceflow/react-chat

voiceflow chat ui

32
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

pmvrmcamandasteinhauerandrewlawrencetylerhhaneffervescentiajosh_vfvoiceflow-gallaganz4o4zsssoflyyyxavidopvf-serviceaccountzhilighttrsytolunsanasarjanjughazyanose-voiceflowdandonovan78theprofabuyakninabondarjbydeleychidi-voiceflowpateriackarjunsehgal-vfrohan-mandhotra-vfmackenzieleudevinabaghmar

Keywords

chatchat widgetai chat botvoiceflow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/styles.css-nDBT7a_Y.js AI (source-diff): Vite/Rollup bundled JS output, not obfuscation. ai
source-diff net-exec-file:build/styles.css-BCg5K3-5.mjs AI (source-diff): Bundled React runtime helpers, no actual net+exec dropper behavior. ai
source-diff net-exec-file:build/styles.css-nDBT7a_Y.js AI (source-diff): Bundled React runtime helpers, no actual net+exec dropper behavior. ai
source-diff obfuscated-file:build/styles.css-BCg5K3-5.mjs AI (source-diff): Vite/Rollup bundled JS output, not obfuscation. ai
source-diff net-exec-file:build/styles.css-B1P_v4FN.mjs AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior. ai
source-diff obfuscated-file:build/styles.css-BY1XhlRN.js AI (source-diff): Bundled Vite output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-BY1XhlRN.js AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior. ai
source-diff obfuscated-file:build/styles.css-B1P_v4FN.mjs AI (source-diff): Bundled Vite output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-Oq9cMn3v.js AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DlMromWW.mjs AI (source-diff): Minified React bundle; no real network+exec payload present. ai
source-diff net-exec-file:build/styles.css-Oq9cMn3v.js AI (source-diff): Minified React bundle; no real network+exec payload present. ai
source-diff obfuscated-file:build/styles.css-DlMromWW.mjs AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-CNfN5ryp.mjs AI (source-diff): False positive from generic bundled build artifact, no real network+exec malware. ai
source-diff obfuscated-file:build/styles.css-CmtHTtma.js AI (source-diff): Bundled Vite/Rollup output, not obfuscation; matches React boilerplate. ai
source-diff obfuscated-file:build/styles.css-CNfN5ryp.mjs AI (source-diff): Bundled Vite/Rollup output, not obfuscation; matches React boilerplate. ai
source-diff net-exec-file:build/styles.css-CmtHTtma.js AI (source-diff): False positive from generic bundled build artifact, no real network+exec malware. ai
source-diff obfuscated-file:build/styles.css-D4MIRDWW.js AI (source-diff): Vite/Rollup bundled output, not obfuscation; matches package build tooling. ai
source-diff net-exec-file:build/styles.css-BrlkRZxa.mjs AI (source-diff): Bundled React interop code, no malicious behavior found. ai
source-diff obfuscated-file:build/styles.css-BrlkRZxa.mjs AI (source-diff): Vite/Rollup bundled ESM output, not obfuscation. ai
source-diff net-exec-file:build/styles.css-D4MIRDWW.js AI (source-diff): React bundle contains normal require/dynamic patterns, no malicious network+exec behavior. ai
source-diff obfuscated-file:build/styles.css-DgqCY0Zc.js AI (source-diff): Minified Vite bundle output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-HUn8aCbR.mjs AI (source-diff): Bundled React/JSX runtime code, no malicious network+exec behavior. ai
source-diff obfuscated-file:build/styles.css-HUn8aCbR.mjs AI (source-diff): Minified Vite bundle output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DgqCY0Zc.js AI (source-diff): Bundled React/JSX runtime code, no malicious network+exec behavior. ai
source-diff net-exec-file:build/styles.css-DkkksYRr.js AI (source-diff): Bundled React runtime code, no real dropper behavior. ai
source-diff net-exec-file:build/styles.css-BHd9n5BQ.mjs AI (source-diff): Bundled React runtime code, no real dropper behavior. ai
source-diff obfuscated-file:build/styles.css-BHd9n5BQ.mjs AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-DkkksYRr.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-DtXR_yLr.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-RZgqP4wo.mjs AI (source-diff): Standard bundle wrapper code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:build/styles.css-RZgqP4wo.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DtXR_yLr.js AI (source-diff): Standard bundle wrapper code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:build/styles.css-Cff6oDf9.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DS-hcqiP.mjs AI (source-diff): Bundled React runtime; no real network+exec malware behavior. ai
source-diff obfuscated-file:build/styles.css-DS-hcqiP.mjs AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-Cff6oDf9.js AI (source-diff): Bundled React runtime; no real network+exec malware behavior. ai
source-diff obfuscated-file:build/styles.css-DWQk1uxg.mjs AI (source-diff): Bundled ESM build output, not obfuscation. ai
source-diff obfuscated-file:build/styles.css-BpybOKZF.js AI (source-diff): Vite/Rollup bundle output (react-jsx-runtime), not true obfuscation. ai
source-diff net-exec-file:build/styles.css-BpybOKZF.js AI (source-diff): Bundled React runtime code; no real network+exec malware behavior found. ai
source-diff net-exec-file:build/styles.css-DWQk1uxg.mjs AI (source-diff): Bundled build artifact, not dropper/loader malware. ai
source-diff obfuscated-file:build/styles.css-C3vCHTeI.mjs AI (source-diff): Minified vite/rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-C3vCHTeI.mjs AI (source-diff): Bundled React/UI code, no actual dropper behavior in sample. ai
source-diff net-exec-file:build/styles.css-BcHMFahz.js AI (source-diff): Bundled React/UI code, no actual dropper behavior in sample. ai
source-diff obfuscated-file:build/styles.css-BcHMFahz.js AI (source-diff): Minified vite/rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:build/ChatConfig.dto-dJlnmvuT.mjs AI (source-diff): Pattern match on bundled React internals, no actual dropper behavior. ai
source-diff obfuscated-file:build/ChatConfig.dto-DZZ2t8yY.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff obfuscated-file:build/ChatConfig.dto-dJlnmvuT.mjs AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:build/ChatConfig.dto-DZZ2t8yY.js AI (source-diff): Pattern match on bundled React internals, no actual dropper behavior. ai
source-diff net-exec-file:build/styles.css-zU0V5IfP.mjs AI (source-diff): Bundler interop helpers, no real network+exec dropper behavior. ai
source-diff obfuscated-file:build/styles.css-qdIlT2BT.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-zU0V5IfP.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-qdIlT2BT.js AI (source-diff): Bundler interop helpers, no real network+exec dropper behavior. ai
source-diff net-exec-file:build/styles.css-BQlrl673.js AI (source-diff): Bundled build output; no real network+exec malware pattern. ai
source-diff obfuscated-file:build/styles.css-yzfJtYUx.mjs AI (source-diff): Bundled Vite/Rollup CSS chunk, minified not obfuscated. ai
source-diff net-exec-file:build/styles.css-yzfJtYUx.mjs AI (source-diff): Bundled build output; no real network+exec malware pattern. ai
source-diff obfuscated-file:build/styles.css-BQlrl673.js AI (source-diff): Bundled Vite/Rollup CSS chunk, minified not obfuscated. ai
source-diff obfuscated-file:build/styles.css-Rk7zZ4Ai.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-BQdXxRlj.mjs AI (source-diff): Bundled React runtime code, no dropper behavior. ai
source-diff obfuscated-file:build/styles.css-BQdXxRlj.mjs AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-Rk7zZ4Ai.js AI (source-diff): Bundled React runtime code, no dropper behavior. ai
source-diff obfuscated-file:build/styles.css-DpVXINrA.mjs AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DpVXINrA.mjs AI (source-diff): Bundled React/jsx-runtime code, no actual network+exec payload. ai
source-diff net-exec-file:build/styles.css-CqdniYZ7.js AI (source-diff): Bundled React/jsx-runtime code, no actual network+exec payload. ai
source-diff obfuscated-file:build/styles.css-CqdniYZ7.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css--cF8_YgW.js AI (source-diff): Bundled UI code; no fetched binary or hostile network target in sample. ai
source-diff net-exec-file:build/styles.css-C5bacpFy.mjs AI (source-diff): Bundled UI code; no malicious network/exec behavior evidenced. ai
source-diff obfuscated-file:build/styles.css-C5bacpFy.mjs AI (source-diff): Vite ESM bundle output, not obfuscation. ai
source-diff obfuscated-file:build/styles.css--cF8_YgW.js AI (source-diff): Vite/rollup bundle output (React license header, module helpers), not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-CIZfRzwF.mjs AI (source-diff): Bundled/minified vite build output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-CIZfRzwF.mjs AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. ai
source-diff net-exec-file:build/styles.css-CK9R2gP0.js AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:build/styles.css-CK9R2gP0.js AI (source-diff): Bundled/minified vite build output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-DplmA48C.mjs AI (source-diff): Standard bundled/minified build output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DplmA48C.mjs AI (source-diff): False positive on bundled React/Vite build code, no real exfil behavior. ai
source-diff net-exec-file:build/styles.css-DCxa62kV.js AI (source-diff): False positive on bundled React/Vite build code, no real exfil behavior. ai
source-diff obfuscated-file:build/styles.css-DCxa62kV.js AI (source-diff): Standard bundled/minified build output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-BEfB8MOo.mjs AI (source-diff): React bundle interop code, no real network+exec malware behavior. ai
source-diff net-exec-file:build/styles.css-DgHrBjvm.js AI (source-diff): React bundle interop code, no real network+exec malware behavior. ai
source-diff obfuscated-file:build/styles.css-BEfB8MOo.mjs AI (source-diff): Bundled Vite/Rollup output, not obfuscation. ai
source-diff obfuscated-file:build/styles.css-DgHrBjvm.js AI (source-diff): Bundled Vite/Rollup output, not obfuscation. ai
source-diff obfuscated-file:build/styles.css-CNo5j7Ek.mjs AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff net-exec-file:build/styles.css-DysXeYfL.js AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:build/styles.css-DysXeYfL.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
publish-pattern dormant-publish AI (publish-pattern): Established monorepo package with sparse release cadence; trusted service-account publisher. ai
source-diff net-exec-file:build/styles.css-CNo5j7Ek.mjs AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:build/styles.css-CUk_oX4E.mjs AI (source-diff): Minified Vite bundle output, not true obfuscation. ai
source-diff obfuscated-file:build/styles.css-BcudssFd.js AI (source-diff): Minified Vite bundle output, not true obfuscation; contains standard React JSX runtime code. ai
source-diff net-exec-file:build/styles.css-CUk_oX4E.mjs AI (source-diff): Bundled React internals, no real network+eval dropper behavior. ai
source-diff net-exec-file:build/styles.css-BcudssFd.js AI (source-diff): Bundled React internals, no real network+eval dropper behavior. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:ts-pattern AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:rehype-raw AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:chroma-js AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Bundled build artifact; declared deps not directly imported is expected for this package. ai
phantom-deps phantom-dep:remeda AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:cuid AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:slate AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
provenance no-provenance AI (provenance): Established Voiceflow org package; lack of provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:@voiceflow/slate-serializer AI (phantom-deps): Same org scope; bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:react-syntax-highlighter AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:react-speech-recognition AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:react-textarea-autosize AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:rehype-external-links AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@paralleldrive/cuid2 AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:regenerator-runtime AI (phantom-deps): Known implicit runtime dependency; stable false positive for this package. ai

Versions (showing 32 of 32)

Version Deps Published
2.62.4 26 / 34
2.11.2 22 / 44
2.11.1 22 / 44
2.11.0 22 / 44
2.10.0 22 / 44
2.9.1 22 / 44
2.9.0 22 / 44
2.8.1 22 / 44
2.8.0 22 / 44
2.7.2 22 / 44
2.7.1 22 / 44
2.7.0 22 / 44
2.6.4 22 / 44
2.6.3 22 / 44
2.6.2 22 / 44
2.6.1 22 / 44
2.6.0 22 / 44
2.5.2 22 / 44
2.5.1 22 / 44
2.5.0 22 / 44
2.4.1 22 / 44
2.4.0 22 / 44
2.3.1 22 / 44
2.3.0 22 / 44
2.2.5 22 / 44
2.2.4 22 / 44
2.2.3 22 / 44
2.2.2 22 / 44
2.2.1 22 / 44
2.2.0 22 / 44
2.1.1 22 / 44
2.1.0 22 / 44

v2.11.2

5 findings
HIGH New obfuscated file: build/ChatConfig.dto-DZZ2t8yY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/ChatConfig.dto-DZZ2t8yY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/ChatConfig.dto-dJlnmvuT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/ChatConfig.dto-dJlnmvuT.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.11.1

5 findings
HIGH New obfuscated file: build/styles.css-nDBT7a_Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-nDBT7a_Y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BCg5K3-5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BCg5K3-5.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.11.0

5 findings
HIGH New obfuscated file: build/styles.css-CqdniYZ7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CqdniYZ7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DpVXINrA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DpVXINrA.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.10.0

5 findings
HIGH New obfuscated file: build/styles.css-CqdniYZ7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CqdniYZ7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DpVXINrA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DpVXINrA.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.1

5 findings
HIGH New obfuscated file: build/styles.css-qdIlT2BT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-qdIlT2BT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-zU0V5IfP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-zU0V5IfP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.0

5 findings
HIGH New obfuscated file: build/styles.css-qdIlT2BT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-qdIlT2BT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-zU0V5IfP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-zU0V5IfP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.1

5 findings
HIGH New obfuscated file: build/styles.css-Oq9cMn3v.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-Oq9cMn3v.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DlMromWW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DlMromWW.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

5 findings
HIGH New obfuscated file: build/styles.css-BQlrl673.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BQlrl673.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-yzfJtYUx.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-yzfJtYUx.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

5 findings
HIGH New obfuscated file: build/styles.css-CmtHTtma.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CmtHTtma.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-CNfN5ryp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CNfN5ryp.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

5 findings
HIGH New obfuscated file: build/styles.css-DtXR_yLr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DtXR_yLr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-RZgqP4wo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-RZgqP4wo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

5 findings
HIGH New obfuscated file: build/styles.css-Rk7zZ4Ai.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-Rk7zZ4Ai.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BQdXxRlj.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BQdXxRlj.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.4

5 findings
HIGH New obfuscated file: build/styles.css-Cff6oDf9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-Cff6oDf9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DS-hcqiP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DS-hcqiP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.3

5 findings
HIGH New obfuscated file: build/styles.css-Cff6oDf9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-Cff6oDf9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DS-hcqiP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DS-hcqiP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.2

5 findings
HIGH New obfuscated file: build/styles.css-BY1XhlRN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BY1XhlRN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-B1P_v4FN.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-B1P_v4FN.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.1

5 findings
HIGH New obfuscated file: build/styles.css-DgqCY0Zc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DgqCY0Zc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-HUn8aCbR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-HUn8aCbR.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

5 findings
HIGH New obfuscated file: build/styles.css-D4MIRDWW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-D4MIRDWW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BrlkRZxa.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BrlkRZxa.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

5 findings
HIGH New obfuscated file: build/styles.css--cF8_YgW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css--cF8_YgW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-C5bacpFy.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-C5bacpFy.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

5 findings
HIGH New obfuscated file: build/styles.css--cF8_YgW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css--cF8_YgW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-C5bacpFy.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-C5bacpFy.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

5 findings
HIGH New obfuscated file: build/styles.css--cF8_YgW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css--cF8_YgW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-C5bacpFy.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-C5bacpFy.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

5 findings
HIGH New obfuscated file: build/styles.css-BcHMFahz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BcHMFahz.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-C3vCHTeI.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-C3vCHTeI.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

5 findings
HIGH New obfuscated file: build/styles.css-CK9R2gP0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CK9R2gP0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-CIZfRzwF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CIZfRzwF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

5 findings
HIGH New obfuscated file: build/styles.css-CK9R2gP0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CK9R2gP0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-CIZfRzwF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CIZfRzwF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

5 findings
HIGH New obfuscated file: build/styles.css-DCxa62kV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DCxa62kV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DplmA48C.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DplmA48C.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.5

5 findings
HIGH New obfuscated file: build/styles.css-DgHrBjvm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DgHrBjvm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BEfB8MOo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BEfB8MOo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.4

5 findings
HIGH New obfuscated file: build/styles.css-DgHrBjvm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DgHrBjvm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BEfB8MOo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BEfB8MOo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.3

5 findings
HIGH New obfuscated file: build/styles.css-DgHrBjvm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DgHrBjvm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BEfB8MOo.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BEfB8MOo.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.2

5 findings
HIGH New obfuscated file: build/styles.css-DysXeYfL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DysXeYfL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-CNo5j7Ek.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CNo5j7Ek.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.1

5 findings
HIGH New obfuscated file: build/styles.css-DkkksYRr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DkkksYRr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-BHd9n5BQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BHd9n5BQ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

5 findings
HIGH New obfuscated file: build/styles.css-BpybOKZF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BpybOKZF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-DWQk1uxg.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-DWQk1uxg.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

5 findings
HIGH New obfuscated file: build/styles.css-BcudssFd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-BcudssFd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/styles.css-CUk_oX4E.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/styles.css-CUk_oX4E.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.