← Home

@vtex/sales-app

Package that contains capabilities to enable estensibility points on Sales App

14
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

eduardoformiganatamelorafarubimvictorhmplurianarturpimentelemersonlaurentinoviniagostinilucasaarcoverdelariciamotageraldo.fernandesmateuspontesvitorlgomesmarcelovicentegcmaianabthiagolcmwendermendescamarathiago.pereira.vtexkevinvtexmyllena.alvesenzomercajardelymarisdaniyelnnrdenissilvavtexvinhagsgeorgebrindeiromarcos_vtexlaisribeirolucasfp13-vtexbrunoamuifdaciuk_vtexsophreisvtexsagginvtexwilliamcunhavtexamandascmvtexgabriel_bozellithaynannunesvtexlab-useryasmintelesguieevc-vtexevertonstrackarthurtriis1vtexmmartinsolivrerissonvtexernestosbarbosawisney.cardealgabriellymourampcardosorafael.pereiraamilton.vtexoremluis.mafraluis.mollmannleidymgdevguilhermeribeiro30

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:public/53fe80cf-c56a34a94121b31c17b9.js AI (source-diff): Webpack bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:public/webpack-runtime-2db6e4a7250e87be80eb.js AI (source-diff): Standard webpack runtime loader, bundler output. ai
source-diff obfuscated-file:public/TurnListScreen-ee32197f55f4689158b6.js AI (source-diff): Gatsby screen bundle, minified build output. ai
source-diff obfuscated-file:public/SalesPerformanceScreen-582bc7c9d1bdf1f26dec.js AI (source-diff): Gatsby screen bundle, minified build output. ai
source-diff obfuscated-file:public/NewProductPage-f7fe346b616236fdc472.js AI (source-diff): Gatsby screen bundle, minified build output. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-517e1c802d4250287bfa.js AI (source-diff): Gatsby bundle chunk loader code, not malicious exfil. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-517e1c802d4250287bfa.js AI (source-diff): Gatsby page component bundle, minified build output. ai
source-diff net-exec-file:public/commons-506006269b2664d5c48a.js AI (source-diff): Bundled prop-types/dom-helpers code, no exfil or fetched-binary behavior. ai
source-diff obfuscated-file:public/commons-506006269b2664d5c48a.js AI (source-diff): Webpack commons chunk, standard bundled deps (prop-types etc). ai
source-diff obfuscated-file:public/CheckoutScreen-6736fbdcc255c0fd4946.js AI (source-diff): Gatsby screen bundle chunk, minified build output. ai
source-diff obfuscated-file:public/6c5962cf-ecb50370f43e61e1d9e5.js AI (source-diff): Webpack bundle chunk, minified build output not obfuscation. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-f638927b85f1b0cd41a8.js AI (source-diff): Bundled app code naturally contains fetch+eval-like patterns from framework internals, not a dropper. ai
maintainer-change maintainer-removed AI (maintainer-change): Routine maintainer roster churn at established publisher with long clean history. ai
source-diff obfuscated-file:public/webpack-runtime-f30aa805c1b2f613e865.js AI (source-diff): Standard webpack runtime file, minified not obfuscated. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-f638927b85f1b0cd41a8.js AI (source-diff): Webpack-bundled Gatsby build output, banner confirms bundler; no malicious behavior shown. ai
source-diff net-exec-file:public/commons-e3a77a6f282c7ddd16fb.js AI (source-diff): Bundled build output; network+eval pattern is normal webpack runtime, not a dropper. ai
dependencies unvetted-dep:handlebars AI (dependencies): Well-known templating library, longstanding dependency. ai
source-diff large-new-source-files AI (source-diff): Expected size for a Gatsby static build output directory. ai
source-diff net-exec-file:public/~partytown/partytown-sw.js AI (source-diff): Partytown library service-worker file, known third-party web-worker offloading tool. ai
source-diff obfuscated-file:public/commons-e3a77a6f282c7ddd16fb.js AI (source-diff): Gatsby/webpack build bundle, long minified lines not obfuscation. ai
source-diff net-exec-file:public/commons-12c017c1ad1bf1069dcb.js AI (source-diff): Bundled webpack chunk, no real net+exec malware pattern. ai
source-diff obfuscated-file:public/app-ae00d76651d5be32a1c7.js AI (source-diff): Webpack bundle output for Gatsby app, not obfuscation. ai
source-diff obfuscated-file:public/CheckoutScreen-adec5ed4ee4859b7a6b9.js AI (source-diff): Webpack bundle output, standard build artifact. ai
source-diff obfuscated-file:public/commons-12c017c1ad1bf1069dcb.js AI (source-diff): Webpack bundle output, standard build artifact. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-1dc994b3852a92680d79.js AI (source-diff): Gatsby webpack build chunk. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-1dc994b3852a92680d79.js AI (source-diff): Bundled webpack chunk, not a dropper. ai
source-diff obfuscated-file:public/ContingencyPaymentScreen-8ba661508dbdfc50c314.js AI (source-diff): Webpack bundle output. ai
source-diff obfuscated-file:public/NewProductPage-3cf825d6292b5c1d8a30.js AI (source-diff): Webpack bundle output. ai
source-diff obfuscated-file:public/SearchScreen-fa38197b8f5c2cf29475.js AI (source-diff): Explicitly labeled bundled minified output. ai
source-diff obfuscated-file:public/TurnListScreen-c53a91941c19752425e5.js AI (source-diff): Webpack bundle output. ai
source-diff obfuscated-file:public/webpack-runtime-776dd9a95941ac2d5139.js AI (source-diff): Webpack runtime chunk, explicitly bundled. ai
publish-pattern new-deps-added AI (publish-pattern): First-party VTEX scoped dependency, consistent with publisher's ecosystem. ai
source-diff obfuscated-file:public/webpack-runtime-fb22f97adcf3d98f4c3f.js AI (source-diff): Standard webpack runtime bundle; minification triggers obfuscation rule as a false positive. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-059bc87339e312410509.js AI (source-diff): Webpack bundle with dynamic chunk loading; net+exec pattern is expected in Gatsby build artifacts. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-059bc87339e312410509.js AI (source-diff): Standard Gatsby/webpack minified bundle; obfuscation flag is a false positive for this build output pattern. ai
source-diff obfuscated-file:public/webpack-runtime-61a4a85a943aa38079ac.js AI (source-diff): Gatsby webpack runtime; minified by build toolchain. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-ad7830d9815f561b10b3.js AI (source-diff): Webpack chunk loader; normal for Gatsby SPA. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-ad7830d9815f561b10b3.js AI (source-diff): Gatsby page bundle; minified by build toolchain. ai
source-diff net-exec-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-deb22f5c76ff5d84cd4f.js AI (source-diff): Dynamic imports are standard Gatsby code-splitting pattern. ai
source-diff net-exec-file:public/commons-4fc313eea52fdf6fe7fb.js AI (source-diff): Dynamic module loading is standard webpack runtime behavior. ai
source-diff obfuscated-file:public/commons-4fc313eea52fdf6fe7fb.js AI (source-diff): Gatsby webpack commons chunk; minification expected. ai
source-diff obfuscated-file:public/CheckoutScreen-e20287933b60d3f9350b.js AI (source-diff): Gatsby webpack chunk; minification is expected for this package. ai
source-diff net-exec-file:public/app-270223972baed44dbad4.js AI (source-diff): Network calls and dynamic module loading are normal webpack runtime patterns in Gatsby bundles. ai
source-diff obfuscated-file:public/app-270223972baed44dbad4.js AI (source-diff): Standard Gatsby/webpack minified bundle; matches package's own gatsby:build script output. ai
source-diff obfuscated-file:public/NewProductPage-4fc14c7eb11b1d5a8f5a.js AI (source-diff): Gatsby webpack chunk; minification expected. ai
source-diff obfuscated-file:public/SalesPerformanceScreen-78dedfa5de92b82f4241.js AI (source-diff): Gatsby webpack chunk; minification expected. ai
source-diff obfuscated-file:public/webpack-runtime-973f08d21488d3297d73.js AI (source-diff): Webpack runtime bundle; new Function() is standard webpack bootstrap pattern. ai
source-diff obfuscated-file:public/ContingencyCartScreen-50b935aede90eb5bb31d.js AI (source-diff): Gatsby webpack chunk; minification expected. ai
source-diff obfuscated-file:public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-deb22f5c76ff5d84cd4f.js AI (source-diff): Gatsby page component bundle; minification expected. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires in webpack-bundled output; standard pattern in React/webpack apps, not obfuscation. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Babel preset loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Babel preset loaded by convention via babel config. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): oclif plugin declared in oclif config, not directly imported. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Babel preset loaded by convention. ai
phantom-deps phantom-dep:@oclif/config AI (phantom-deps): oclif config dep loaded by framework convention. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type-only package, not directly imported. ai
phantom-deps phantom-dep:webpack-cli AI (phantom-deps): CLI tool referenced in scripts, not imported in source. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped, loaded by babel-loader convention. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Build-tool dep used via tsconfig/tsc, not directly imported in source. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in webpack-runtime bundle; webpack uses new Function() internally for module loading. ai
phantom-deps phantom-dep:cookie-parser AI (phantom-deps): Used in express server config, not directly imported in analyzed source. ai
phantom-deps phantom-dep:@types/react-dom AI (phantom-deps): Type-only package, not directly imported. ai

Versions (showing 14 of 14)

Version Deps Published
3.54.0 30 / 16
3.53.7 30 / 14
3.53.3 29 / 14
3.50.0 29 / 14
3.49.8 29 / 14
3.49.5 30 / 14
3.49.4 30 / 14
3.49.3 30 / 14
3.49.0 30 / 14
3.48.0 30 / 14
3.47.4 29 / 14
3.45.0 29 / 14
3.43.3 29 / 14
3.42.4 29 / 14

v3.54.0

4 findings
HIGH New obfuscated file: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-f638927b85f1b0cd41a8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-f638927b85f1b0cd41a8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/webpack-runtime-f30aa805c1b2f613e865.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.53.7

12 findings
HIGH New obfuscated file: public/app-ae00d76651d5be32a1c7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/CheckoutScreen-adec5ed4ee4859b7a6b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/commons-12c017c1ad1bf1069dcb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/commons-12c017c1ad1bf1069dcb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-1dc994b3852a92680d79.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-1dc994b3852a92680d79.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/ContingencyPaymentScreen-8ba661508dbdfc50c314.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/NewProductPage-3cf825d6292b5c1d8a30.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/SearchScreen-fa38197b8f5c2cf29475.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/TurnListScreen-c53a91941c19752425e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/webpack-runtime-776dd9a95941ac2d5139.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.53.3

40 findings
HIGH New obfuscated file: public/0648ef6d-08d62dc50f98cc85bed6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/255-bb093c2c8089ea07d08f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/296-38eea20218bb22b98663.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/2c327f8c-e0c1a03e3e500e53bb44.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/31-ccc8bce60558652e27b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/31f2e9b4-5612fd278dd1d83eae11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/504-3f7f1f3a98fe9ccca6d7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/53fe80cf-e343f4e4953b3a9e3159.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/669-8edf21b9d6237e91aabf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/695-db4c9b8cba3edb9bb59c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/6a362bc8-453458863f1117f35c8f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/6c5962cf-df29c9328ca843f90d8f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/767-9f84a65a99b5ab4ed7f7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/812-090aa44f53327626fa31.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/839-f991eace859689e2fd6b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/a29ae703-a0df39b3934be8485eba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/app-1a3819478f6ebc113889.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/b91d71a0-6ede6e8ce4392a3280e7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/CheckoutInstoreSprite-3629343062fbff329634.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/CheckoutScreen-09d4ebd1e64fd83bdd90.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/commons-0834eec57e66ad823e0e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/commons-0834eec57e66ad823e0e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-8c0b013ce6344b60ad15.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-8c0b013ce6344b60ad15.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/ContingencyCartScreen-dc525d6e74780152f78a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/ContingencyOrderDetailsScreen-bf3a7cfa56588f0e0521.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/ContingencyOrderPlacedScreen-eef6f2ec2e8096044a31.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/ContingencyOrdersScreen-30e68fe978cdfa7ffbf2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: public/ContingencyPaymentScreen-7553072b294cb110f712.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/de10f836-c23e7b694bf3f6b6aed8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/framework-39a18f2df1c173efb61b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/NewProductPage-21eeb8fde33af12fdcb7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/~partytown/partytown-atomics.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/~partytown/partytown-atomics.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: public/~partytown/partytown-media.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: public/~partytown/partytown-sw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: public/~partytown/partytown-sw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/~partytown/debug/partytown-ww-atomics.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/~partytown/debug/partytown-ww-sw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.45.0

12 findings
HIGH New obfuscated file: public/53fe80cf-c56a34a94121b31c17b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/6c5962cf-ecb50370f43e61e1d9e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/CheckoutScreen-6736fbdcc255c0fd4946.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/commons-506006269b2664d5c48a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/commons-506006269b2664d5c48a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-517e1c802d4250287bfa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: public/component---gatsby-theme-instore-core-src-screens-instore-index-tsx-517e1c802d4250287bfa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/NewProductPage-f7fe346b616236fdc472.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/SalesPerformanceScreen-582bc7c9d1bdf1f26dec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/TurnListScreen-ee32197f55f4689158b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: public/webpack-runtime-2db6e4a7250e87be80eb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.43.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.42.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.