@volcengine/veplayer
火山引擎 Web 播放器
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:eventemitter3 | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:js-cookie | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:xgplayer-service | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:proxy-polyfill | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| phantom-deps | phantom-dep:globalthis-polyfill | AI (phantom-deps): Minified dist build; no scannable imports for legitimate deps. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vcloud_fe is an established maintainer, not a new/unknown account. | ai | |
| source-diff | net-exec-file:index.min.js | AI (source-diff): Minified UMD bundle of a video player, not a dropper; pattern recurs across releases. | ai | |
| source-diff | obfuscated-file:plugin/hlsjsPro.js | AI (source-diff): Bundled hls.js plugin with build banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:plugin/hlsjsPro.js | AI (source-diff): Bundled player plugin; network+exec is normal media-loading, no hostile target. | ai | |
| source-diff | obfuscated-file:plugin/xgHls.js | AI (source-diff): Bundled xgplayer HLS plugin, minified build output. | ai | |
| source-diff | encoded-string-file:index.min.js | AI (source-diff): Minified main bundle with version banner; long strings are normal. | ai | |
| source-diff | encoded-string-file:plugin/hlsEncrypt.js | AI (source-diff): Bundled DRM/HLS-encrypt plugin; encoded strings expected. | ai | |
| source-diff | encoded-string-file:plugin/XGVideo.js | AI (source-diff): Bundled xgplayer video plugin build output. | ai | |
| source-diff | encoded-string-file:umd/veplayer.production.js | AI (source-diff): Bundled minified player output; stable across versions. | ai | |
| source-diff | encoded-string-file:esm/veplayer.production.js | AI (source-diff): Bundled minified player output with internal URL-encoding scheme; stable across versions. | ai | |
| source-diff | encoded-string-file:umd/veplayer.live.development.js | AI (source-diff): Bundled data tables, consistent across all build variants. | ai | |
| source-diff | encoded-string-file:esm/veplayer.live.development.js | AI (source-diff): Bundled data tables, consistent across all build variants. | ai | |
| source-diff | encoded-string-file:umd/veplayer.biz.live.production.js | AI (source-diff): Minified bundler output, no malicious behavior found. | ai | |
| source-diff | encoded-string-file:esm/veplayer.biz.live.production.js | AI (source-diff): Minified bundler output, no malicious behavior found. | ai | |
| source-diff | encoded-string-file:umd/veplayer.biz.live.development.js | AI (source-diff): Same bundled build artifact as esm counterpart. | ai | |
| source-diff | encoded-string-file:esm/veplayer.biz.live.development.js | AI (source-diff): Bundled lookup tables/zip-signature fixture, not exec-of-decoded-payload. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established official Volcengine SDK, metadata sparsity is not spam. | ai | |
| source-diff | encoded-string-file:umd/veplayer.development.js | AI (source-diff): Same pattern as esm counterpart, benign. | ai | |
| source-diff | encoded-string-file:esm/veplayer.development.js | AI (source-diff): Encoded strings are region config tables, not payloads. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 2.12.1 | 0 / 0 | |
| 2.12.0 | 0 / 0 | |
| 2.11.2 | 0 / 0 | |
| 2.11.1 | 0 / 0 | |
| 2.11.0 | 0 / 0 | |
| 2.10.3 | 0 / 0 | |
| 2.10.2 | 0 / 0 | |
| 2.10.1 | 0 / 0 | |
| 1.17.0 | 0 / 0 | |
| 1.16.0 | 0 / 0 | |
| 1.8.1 | 0 / 0 | |
| 1.8.0 | 0 / 0 | |
| 1.7.6 | 0 / 0 | |
| 1.7.5 | 0 / 0 | |
| 1.7.4 | 0 / 0 | |
| 1.7.2 | 0 / 0 | |
| 1.7.1 | 0 / 0 | |
| 1.7.0 | 0 / 0 | |
| 1.6.4 | 0 / 0 | |
| 1.6.3 | 0 / 0 | |
| 1.6.2 | 0 / 0 | |
| 1.6.1 | 0 / 0 | |
| 1.6.0 | 0 / 0 | |
| 1.5.16 | 0 / 27 | |
| 1.5.13 | 0 / 27 | |
| 1.5.10 | 0 / 27 | |
| 1.5.9 | 0 / 27 | |
| 1.5.8 | 14 / 27 | |
| 1.4.1 | 0 / 27 |
v2.11.2
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.3
13 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 28 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.8.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-31, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-25, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-12, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-11, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2024-01-04, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-12-15, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-12-15, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-11-07, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-10-20, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-10-12, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-09-22, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-09-14, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.6.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (vcloud_fe) than the most recent previously approved version (chenyongjin) on 2023-08-18, but vcloud_fe is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.5.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: chenyongjin.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.