← Home

@vue-skuilder/standalone-ui

40
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

nilock

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/assets/common-ui.es-DDvhbVBP.js AI (source-diff): Vite bundler banner present; minified build output. ai
source-diff obfuscated-file:dist/assets/index-CQnBgFOT.js AI (source-diff): Vite bundler entry chunk, standard build output. ai
source-diff net-exec-file:dist/assets/dist-CDEq0Y3a.js AI (source-diff): Bundled build output; no malicious network/exec behavior shown. ai
source-diff obfuscated-file:dist/assets/dist-CDEq0Y3a.js AI (source-diff): Bundled commonJS shims (spark-md5 etc.), not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-DDvhbVBP.js AI (source-diff): Standard bundled vue-router/network code, no dropper behavior evident. ai
source-diff net-exec-file:dist/assets/common-ui.es-CS663iWK.js AI (source-diff): Bundled router/framework code, no exfil behavior evident. ai
source-diff net-exec-file:dist/assets/dist-DHtsWAkb.js AI (source-diff): Bundled vendor code, no malicious network target found. ai
source-diff obfuscated-file:dist/assets/common-ui.es-CS663iWK.js AI (source-diff): Vite bundle chunk; standard framework internals visible. ai
source-diff obfuscated-file:dist/assets/dist-DHtsWAkb.js AI (source-diff): Bundled spark-md5/vendor libs, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/index-Cib2NGQ_.js AI (source-diff): Vite entrypoint bundle, standard module-preload polyfill code. ai
source-diff obfuscated-file:dist/assets/dist-mJg7wGOe.js AI (source-diff): Vendored spark-md5/vue-router bundle, not obfuscation. ai
source-diff net-exec-file:dist/assets/dist-mJg7wGOe.js AI (source-diff): No hostile network target identified; standard bundle. ai
source-diff obfuscated-file:dist/assets/index-BTx-tECR.js AI (source-diff): Vite entry bundle with modulepreload polyfill, not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-CKDaicTB.js AI (source-diff): Standard bundler fetch/eval patterns, no exfil destination. ai
source-diff obfuscated-file:dist/assets/common-ui.es-CKDaicTB.js AI (source-diff): Vite bundle output with matching sourcemap. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DhLJkoaY.js AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/assets/dist-CIWSsb1y.js AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/dist-CIWSsb1y.js AI (source-diff): Bundled vendor lib (spark-md5) plus module code, no malicious network target. ai
source-diff obfuscated-file:dist/assets/index-CIllvcxx.js AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-DhLJkoaY.js AI (source-diff): Standard fetch/module-preload code in bundled Vue webapp, no exfiltration target. ai
source-diff net-exec-file:dist/assets/common-ui.es-DAD-mXog.js AI (source-diff): Bundled fetch/dynamic-import polyfill pattern, no malicious target. ai
source-diff obfuscated-file:dist/assets/dist-BYBX0RyH.js AI (source-diff): Bundled spark-md5/vue-router deps, minified not obfuscated. ai
source-diff net-exec-file:dist/assets/dist-BYBX0RyH.js AI (source-diff): Bundled code, no exfil/dropper behavior evident. ai
source-diff obfuscated-file:dist/assets/index-Ch4dDCy5.js AI (source-diff): Vite entry bundle, standard modulepreload polyfill. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DAD-mXog.js AI (source-diff): Vite-bundled internal package output. ai
source-diff obfuscated-file:dist/assets/index-9XwHN2NO.js AI (source-diff): Vite entry bundle with module preload polyfill, standard build output. ai
source-diff net-exec-file:dist/assets/common-ui.es-BFeiYXxe.js AI (source-diff): Bundled fetch/module-loader polyfill code, not dropper behavior. ai
source-diff net-exec-file:dist/assets/dist-BKY5mgTZ.js AI (source-diff): Bundled vendor code, no malicious network behavior found. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package metadata style, consistent across siblings, not spam. ai
source-diff obfuscated-file:dist/assets/common-ui.es-BFeiYXxe.js AI (source-diff): Bundled common-ui asset, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/dist-BKY5mgTZ.js AI (source-diff): Bundled vendor libs (spark-md5 etc), minified not obfuscated. ai
source-diff net-exec-file:dist/assets/dist-BA5iGova.js AI (source-diff): Bundled lib code (spark-md5 etc.), no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/assets/index-jVsEPQR7.js AI (source-diff): Vite entry bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/dist-BA5iGova.js AI (source-diff): Bundled output incl. spark-md5 lib, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DlYghJUY.js AI (source-diff): Vite/Rollup bundled output, minified not obfuscated. ai
source-diff net-exec-file:dist/assets/common-ui.es-DlYghJUY.js AI (source-diff): Standard modulepreload/fetch polyfill in bundled webapp, not a dropper. ai
source-diff obfuscated-file:dist/assets/common-ui.es-Dt1DQMFY.js AI (source-diff): Vite-bundled vendor chunk, not obfuscation. ai
source-diff obfuscated-file:dist/assets/dist-CDhtG9sH.js AI (source-diff): Vite-bundled vendor chunk (spark-md5 etc), not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-Dt1DQMFY.js AI (source-diff): Standard bundled fetch/dynamic import polyfill, no exfil behavior. ai
source-diff net-exec-file:dist/assets/dist-CDhtG9sH.js AI (source-diff): Standard bundled fetch/dynamic import polyfill, no exfil behavior. ai
source-diff obfuscated-file:dist/assets/index-DuGLD7Ss.js AI (source-diff): Vite-bundled app entry chunk with modulepreload polyfill, not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-DsyLvwIV.js AI (source-diff): Vite-bundled vue-router code, no malicious destination. ai
source-diff net-exec-file:dist/assets/index-D_Z-_zpu.js AI (source-diff): Vite bundler banner confirmed; main app bundle. ai
source-diff obfuscated-file:dist/assets/index-D_Z-_zpu.js AI (source-diff): Vite bundler banner confirmed; main app bundle. ai
source-diff net-exec-file:dist/assets/dist-GwWsrg82.js AI (source-diff): Bundled output, no concrete malicious behavior found. ai
source-diff obfuscated-file:dist/assets/dist-GwWsrg82.js AI (source-diff): Same bundled build artifact pattern as sibling files. ai
source-diff obfuscated-file:dist/assets/dist-D4fpn-Cc.js AI (source-diff): Standard rolldown/vite bundler preamble, minified moment.js etc. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DsyLvwIV.js AI (source-diff): Vite bundler banner confirmed; standard build output. ai
source-diff obfuscated-file:dist/assets/MarkdownRenderer-DoVbFpA6-Cj6PSy5i.js AI (source-diff): Vite-bundled build output. ai
source-diff net-exec-file:dist-lib/dist-COeuceiv.js AI (source-diff): eval("require")("fs") is a standard bundler Node/browser interop shim. ai
source-diff obfuscated-file:dist-lib/dist-COeuceiv.js AI (source-diff): Bundled deps (spark-md5 etc.), minified not obfuscated. ai
source-diff net-exec-file:dist-lib/common-ui.es-CI3A9lXQ.js AI (source-diff): Bundled Vue compiler code, no malicious network/exec behavior. ai
source-diff obfuscated-file:dist-lib/MarkdownRenderer-DoVbFpA6-DSu2Rt-U.js AI (source-diff): Vite/rollup bundled Vue runtime, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/index-CKWL4yvm.js AI (source-diff): Vite-bundled webapp output, minified not obfuscated. ai
source-diff net-exec-file:dist/assets/index-CKWL4yvm.js AI (source-diff): Standard fetch/module-preload code in bundled SPA, no malicious target. ai
source-diff net-exec-file:dist/assets/common-ui.es-ibXGK5ti.js AI (source-diff): Standard bundled router/fetch polyfill code, no exfil target. ai
source-diff obfuscated-file:dist/assets/common-ui.es-ibXGK5ti.js AI (source-diff): Vite bundle banner confirms build output. ai
source-diff obfuscated-file:dist/assets/dist-DlSLFgY8.js AI (source-diff): Bundled SparkMD5/vendor lib, not obfuscation. ai
source-diff net-exec-file:dist/assets/dist-DlSLFgY8.js AI (source-diff): Bundled vendor code; no malicious network destination. ai
source-diff obfuscated-file:dist/assets/index-CKXq4U_A.js AI (source-diff): Vite entry chunk with modulepreload polyfill, standard bundler output. ai
source-diff net-exec-file:dist/assets/index-DF3SIdoO.js AI (source-diff): fetch()+eval-like patterns are vite/vue framework boilerplate, no hostile target. ai
source-diff obfuscated-file:dist/assets/index-DF3SIdoO.js AI (source-diff): Vite bundle output, not true obfuscation; standard minified webapp asset. ai
source-diff obfuscated-file:dist/assets/index-DAcpxSe7.js AI (source-diff): Standard Vite/Vue minified bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-DAcpxSe7.js AI (source-diff): fetch used for module preloading in bundled Vite runtime, not exfil. ai
source-diff obfuscated-file:dist/assets/index-BwHrrJl0.js AI (source-diff): Vite/Rollup bundled webapp output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-BwHrrJl0.js AI (source-diff): Standard fetch-based modulepreload polyfill in bundled Vite output. ai
source-diff obfuscated-file:dist/assets/dist-D6tRtHge.js AI (source-diff): Bundled vendor code (spark-md5), minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/index-CDRvg5QJ.js AI (source-diff): Standard Vite entry bundle, minified not obfuscated. ai
source-diff net-exec-file:dist/assets/dist-D6tRtHge.js AI (source-diff): Bundled vendor library, no malicious network destination found. ai
source-diff net-exec-file:dist/assets/common-ui.es-RbbhjMGz.js AI (source-diff): Bundler module-preload polyfill fetch/import pattern, not exfil. ai
source-diff obfuscated-file:dist/assets/common-ui.es-RbbhjMGz.js AI (source-diff): Bundled build output from monorepo shared package. ai
source-diff net-exec-file:dist/assets/index-CbJoDxlk.js AI (source-diff): Vite modulepreload fetch polyfill, standard bundle pattern, no malicious target. ai
source-diff obfuscated-file:dist/assets/index-CbJoDxlk.js AI (source-diff): Vite bundle minification, not obfuscation. ai
source-diff obfuscated-file:dist/assets/index-DDNsNEHf.js AI (source-diff): Vite bundle output, not obfuscation. ai
source-diff net-exec-file:dist/assets/index-DDNsNEHf.js AI (source-diff): Standard fetch/preload code in Vite bundle. ai
source-diff net-exec-file:dist/assets/index-DsPjKJpe.js AI (source-diff): Standard Vite modulepreload/fetch polyfill, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/index-DsPjKJpe.js AI (source-diff): Vite-bundled webapp output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-DXjEpSH8.js AI (source-diff): Standard vite modulepreload fetch logic, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-DXjEpSH8.js AI (source-diff): Vite bundle banner/minified output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/dist-SoAs4WNl.js AI (source-diff): Bundled router/util code, no hostile network target. ai
source-diff obfuscated-file:dist/assets/index-Bg37fxGA.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/dist-SoAs4WNl.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/common-ui.es-CIGym5zn.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/assets/common-ui.es-CIGym5zn.js AI (source-diff): fetch+dynamic import is Vite's own module-preload polyfill, not dropper behavior. ai
source-diff net-exec-file:dist/assets/index-Cr_Q6ieW.js AI (source-diff): Bundler preload/fetch helpers, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-Cr_Q6ieW.js AI (source-diff): Standard Vite bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-C69g2NQ7.js AI (source-diff): Standard Vite fetch/modulepreload polyfill in bundle, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-C69g2NQ7.js AI (source-diff): Vite-bundled webapp output, not true obfuscation. ai
source-diff obfuscated-file:dist/assets/index-zm234ck7.js AI (source-diff): Standard Vite bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-zm234ck7.js AI (source-diff): fetch used for CSS/module preload polyfill, not exfil/dropper. ai
source-diff obfuscated-file:dist/assets/index-Cz0N_PW4.js AI (source-diff): Vite/webpack bundled webapp output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-Cz0N_PW4.js AI (source-diff): Standard fetch+modulepreload polyfill in bundled front-end code, no malicious target. ai
source-diff net-exec-file:dist/assets/index-B3b_lZhk.js AI (source-diff): Vite modulepreload fetch polyfill, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/index-B3b_lZhk.js AI (source-diff): Vite bundle output, not true obfuscation. ai
source-diff obfuscated-file:dist/assets/index-PkV5qi5_.js AI (source-diff): Vite build bundler output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-PkV5qi5_.js AI (source-diff): Standard Vite modulepreload fetch polyfill, not a dropper. ai
source-diff net-exec-file:dist/assets/index-D3NtHgqQ.js AI (source-diff): Standard Vite modulepreload fetch logic, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-D3NtHgqQ.js AI (source-diff): Vite-bundled webapp output, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-BFPAwWXV.js AI (source-diff): Standard Vite modulepreload/fetch polyfill code, not dropper behavior. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are same-org monorepo packages and well-known 'events' polyfill. ai
source-diff obfuscated-file:dist/assets/index-BFPAwWXV.js AI (source-diff): Vite bundler output, not true obfuscation; no malicious behavior. ai
source-diff net-exec-file:dist/assets/common-ui.es-_Nay4Hg9.js AI (source-diff): Network calls and dynamic imports are normal Vite lazy-loading patterns in this UI bundle. ai
source-diff obfuscated-file:dist/assets/index-lmLOFur1.js AI (source-diff): Standard Vite entry bundle with modulepreload polyfill; not obfuscation. ai
source-diff net-exec-file:dist/assets/dist-DHzymw-6.js AI (source-diff): Network + dynamic code patterns are Vite bundle artifacts, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/dist-DHzymw-6.js AI (source-diff): Standard Vite minified bundle; sample shows spark-md5 and known library code. ai
source-diff obfuscated-file:dist/assets/common-ui.es-_Nay4Hg9.js AI (source-diff): Standard Vite minified bundle output for this package; not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-BLg_8nr-.js AI (source-diff): Network calls are vue-router fetch/preload polyfills; dynamic code is module loading, not malware. ai
source-diff obfuscated-file:dist/assets/index-BUyUeqxf.js AI (source-diff): Vite webapp entry bundle; minification is expected for this package type. ai
source-diff net-exec-file:dist/assets/dist-Dw3a5Op4.js AI (source-diff): Same bundle; network/exec pattern is module loading infrastructure, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/dist-Dw3a5Op4.js AI (source-diff): Standard Vite minified bundle; identifiable as spark-md5 and project-specific exports. ai
source-diff obfuscated-file:dist/assets/common-ui.es-BLg_8nr-.js AI (source-diff): Standard Vite minified bundle output for a Vue UI library; not obfuscation. ai
source-diff net-exec-file:dist/assets/common-ui.es-Bh7QiFa1.js AI (source-diff): Network calls and dynamic imports are normal Vue SPA routing patterns (vue-router lazy loading). ai
source-diff obfuscated-file:dist/assets/index-BOK-JsV6.js AI (source-diff): Standard Vite minified entry bundle with __vite__mapDeps; legitimate build artifact. ai
source-diff net-exec-file:dist/assets/dist--Dpfoemh.js AI (source-diff): Network/dynamic patterns are standard bundled library code, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/dist--Dpfoemh.js AI (source-diff): Standard Vite minified bundle; spark-md5 and other readable identifiers confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/assets/common-ui.es-Bh7QiFa1.js AI (source-diff): Standard Vite minified bundle output; readable identifiers confirm legitimate build artifact. ai
source-diff net-exec-file:dist/assets/common-ui.es-B6UqZKxa.js AI (source-diff): Network calls and dynamic imports are Vite lazy-loading patterns, not dropper behavior. ai
phantom-deps phantom-dep:@vue-skuilder/courseware AI (phantom-deps): Same-org monorepo dep bundled into dist output. ai
phantom-deps phantom-dep:@vue-skuilder/common-ui AI (phantom-deps): Same-org monorepo dep bundled into dist output. ai
phantom-deps phantom-dep:@vue-skuilder/common AI (phantom-deps): Same-org monorepo dep bundled into dist output. ai
phantom-deps phantom-dep:@vue-skuilder/db AI (phantom-deps): Same-org monorepo dep bundled into dist output. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): Bundled into dist; router code visible in samples. ai
phantom-deps phantom-dep:@mdi/font AI (phantom-deps): Icon font asset dep; referenced in Vite config not source imports. ai
phantom-deps phantom-dep:vuetify AI (phantom-deps): UI framework bundled into dist; declared as dep for consumers. ai
phantom-deps phantom-dep:events AI (phantom-deps): Node events polyfill used via Vite config, not direct import. ai
phantom-deps phantom-dep:pinia AI (phantom-deps): Vue ecosystem peer dep bundled into dist; not directly imported in source but legitimately declared. ai
source-diff obfuscated-file:dist/assets/index-5H45bc-8.js AI (source-diff): Vite entry bundle with modulepreload polyfill; standard SPA build artifact. ai
source-diff net-exec-file:dist/assets/dist-B6gIbmvQ.js AI (source-diff): Same Vite bundle pattern; dynamic code execution is AMD/CJS interop shim, not malicious loader. ai
source-diff obfuscated-file:dist/assets/dist-B6gIbmvQ.js AI (source-diff): Standard Vite-minified bundle; contains spark-md5 and project-specific exports, not obfuscated malware. ai
source-diff obfuscated-file:dist/assets/common-ui.es-B6UqZKxa.js AI (source-diff): Standard Vite-minified bundle output for a Vue SPA; source maps present, content is recognizable Vue/router code. ai
source-diff net-exec-file:dist/assets/dist-BoYWClge.js AI (source-diff): Vite webapp bundle; network calls are application-level API calls. ai
source-diff net-exec-file:dist/assets/common-ui.es-Dli7wjjJ.js AI (source-diff): Vite webapp bundle; network calls are application-level API calls. ai
source-diff obfuscated-file:dist/assets/index-Di-iurxs.js AI (source-diff): Standard Vite minified bundle output for this UI package. ai
source-diff obfuscated-file:dist/assets/dist-BoYWClge.js AI (source-diff): Standard Vite minified bundle output for this UI package. ai
source-diff obfuscated-file:dist/assets/common-ui.es-Dli7wjjJ.js AI (source-diff): Standard Vite minified bundle output for this UI package. ai
source-diff obfuscated-file:dist/assets/index-rJK7G7mT.js AI (source-diff): Standard Vite minified bundle output for a Vue UI library. ai
source-diff obfuscated-file:dist/assets/dist-CglDOuwn.js AI (source-diff): Standard Vite minified bundle output for a Vue UI library. ai
source-diff obfuscated-file:dist/assets/common-ui.es-CIp6hqfh.js AI (source-diff): Standard Vite minified bundle output for a Vue UI library. ai
source-diff net-exec-file:dist/assets/dist-CglDOuwn.js AI (source-diff): Vite webapp bundle; network calls are application-level API calls, not malware. ai
source-diff net-exec-file:dist/assets/common-ui.es-CIp6hqfh.js AI (source-diff): Vite webapp bundle; network calls are application-level API calls, not malware. ai
source-diff obfuscated-file:dist/assets/index-e8XolFvR.js AI (source-diff): Vite bundle; same pattern as other dist assets. ai
source-diff obfuscated-file:dist/assets/dist-BcZ1gsNX.js AI (source-diff): Vite bundle; same pattern as other dist assets. ai
source-diff obfuscated-file:dist-lib/dist-BP0_sJdJ.js AI (source-diff): Vite bundle of @vue-skuilder/db and spark-md5; recognizable OSS code. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DfgaTZ4z.js AI (source-diff): Vite-minified common-ui bundle with vue-router; standard build output. ai
source-diff net-exec-file:dist/assets/dist-BcZ1gsNX.js AI (source-diff): Vite bundle; same pattern. ai
source-diff net-exec-file:dist/assets/common-ui.es-DfgaTZ4z.js AI (source-diff): Same as dist-lib counterpart; Vite dynamic imports + Vue compiler. ai
source-diff net-exec-file:dist-lib/dist-BP0_sJdJ.js AI (source-diff): eval('require') is a standard Node env-detection pattern; network calls are PouchDB/fetch; not malicious. ai
source-diff net-exec-file:dist-lib/common-ui.es-B8Tew0sr.js AI (source-diff): Network calls are Vue dynamic imports (__vite__mapDeps); exec is Vue compiler; no dropper behavior. ai
source-diff net-exec-file:dist/assets/common-ui.es-DQVvqecz.js AI (source-diff): Network calls are Vue Router/fetch patterns in minified bundle; not dropper behavior. ai
source-diff net-exec-file:dist-lib/questions.mjs AI (source-diff): Network calls are app API patterns in minified ESM library build. ai
source-diff obfuscated-file:dist-lib/questions.mjs AI (source-diff): Rolldown ESM library build; minification is expected for this package. ai
source-diff obfuscated-file:dist/assets/index-CgJHLYRy.js AI (source-diff): Minified Vite bundle; consistent with this package's build output. ai
source-diff net-exec-file:dist/assets/dist-D0Pw05KO.js AI (source-diff): Network calls are standard app API calls in minified bundle. ai
source-diff obfuscated-file:dist/assets/dist-D0Pw05KO.js AI (source-diff): Minified Vite bundle with spark-md5 and app logic; no malicious indicators. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DQVvqecz.js AI (source-diff): Standard Vite minified bundle output; stable pattern for this UI package. ai
source-diff obfuscated-file:dist-lib/dist-D3TZHmH5.js AI (source-diff): Minified Vite bundle of open-source deps (spark-md5, etc.); expected for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in Vue reactivity proxy handlers; standard Vue 3 internals pattern. ai
semgrep semgrep:eval-usage AI (semgrep): eval('require') is a standard esbuild/Vite CJS shim for Node.js fs detection; not user-controlled. ai
source-diff large-new-source-files AI (source-diff): 22 new files are Vite build artifacts from newly added build:lib and build:webapp scripts. ai
source-diff source-size-tripled AI (source-diff): Package now ships full Vite dist; size jump is structural, not injection. ai
source-diff obfuscated-file:dist/assets/index-C6NB1IPv.js AI (source-diff): Minified Vite webapp entry; expected build artifact. ai
source-diff obfuscated-file:dist/assets/dist-DCANvFNh.js AI (source-diff): Minified Vite bundle; expected build artifact. ai
source-diff net-exec-file:dist/assets/dist-BC_KquM-.js AI (source-diff): Same Vite bundle pattern; no malicious network behavior identified. ai
source-diff obfuscated-file:dist/assets/dist-BC_KquM-.js AI (source-diff): Minified Vite bundle; expected build artifact. ai
source-diff net-exec-file:dist/assets/common-ui.es-DxZNthuJ.js AI (source-diff): Dynamic imports via __vite__mapDeps are standard Vite lazy-loading, not malware. ai
source-diff obfuscated-file:dist/assets/common-ui.es-DxZNthuJ.js AI (source-diff): Minified Vite webapp asset with vue-router and component code; expected. ai
source-diff obfuscated-file:dist/assets/MarkdownRenderer-DoVbFpA6-DYVMsbBP.js AI (source-diff): Minified Vite webapp asset; same Vue compiler code as lib build. ai
source-diff obfuscated-file:dist-lib/MarkdownRenderer-DoVbFpA6-BjR5e6Al.js AI (source-diff): Standard Vite/Vue bundled output; minification is expected for this build-output package. ai
source-diff net-exec-file:dist-lib/questions.cjs.js AI (source-diff): CJS bundle entry point; inline font data and standard Vue component code, not dropper. ai
source-diff net-exec-file:dist-lib/dist-D3TZHmH5.js AI (source-diff): eval('require') pattern is a known Vite/esbuild CJS shim for Node detection; not malicious. ai
source-diff net-exec-file:dist-lib/common-ui.es-BndKNv1Z.js AI (source-diff): Vite-bundled Vue app; network calls are fetch/XHR in Vue router/component code, not dropper behavior. ai

Versions (showing 40 of 40)

Version Deps Published
0.2.16 10 / 9
0.2.15 10 / 9
0.2.14 10 / 9
0.2.13 10 / 9
0.2.12 10 / 9
0.2.11 10 / 9
0.2.10 10 / 9
0.2.9 10 / 9
0.2.8 10 / 9
0.2.7 10 / 9
0.2.5 10 / 9
0.2.4 10 / 9
0.2.3 10 / 9
0.2.2 10 / 9
0.2.1 10 / 9
0.2.0 10 / 9
0.1.40 10 / 9
0.1.39 10 / 9
0.1.38 10 / 9
0.1.36 10 / 9
0.1.35 10 / 9
0.1.33 10 / 9
0.1.31 10 / 9
0.1.30 10 / 9
0.1.29 10 / 9
0.1.28 10 / 9
0.1.27 10 / 9
0.1.26 10 / 9
0.1.25 10 / 9
0.1.24 10 / 9
0.1.23 10 / 9
0.1.22 10 / 9
0.1.21 10 / 9
0.1.20 10 / 9
0.1.18 10 / 9
0.1.17 10 / 9
0.1.16 10 / 9
0.1.15 10 / 9
0.1.14 10 / 9
0.1.1 7 / 7

v0.2.16

7 findings
HIGH New obfuscated file: dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-DDvhbVBP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/common-ui.es-DDvhbVBP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/assets/dist-CDEq0Y3a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-CDEq0Y3a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-CQnBgFOT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

7 findings
HIGH New obfuscated file: dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-ibXGK5ti.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/common-ui.es-ibXGK5ti.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/assets/dist-DlSLFgY8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-DlSLFgY8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-CKXq4U_A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

7 findings
HIGH New obfuscated file: dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-CS663iWK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/common-ui.es-CS663iWK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/assets/dist-DHtsWAkb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-DHtsWAkb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-Cib2NGQ_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

7 findings
HIGH New obfuscated file: dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-CKDaicTB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/common-ui.es-CKDaicTB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/assets/dist-mJg7wGOe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-mJg7wGOe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-BTx-tECR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

7 findings
HIGH New obfuscated file: dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-DhLJkoaY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/common-ui.es-DhLJkoaY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/dist-CIWSsb1y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-CIWSsb1y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-CIllvcxx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.33

13 findings
HIGH New obfuscated file: dist-lib/MarkdownRenderer-DoVbFpA6-DSu2Rt-U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist-lib/common-ui.es-CI3A9lXQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist-lib/dist-COeuceiv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist-lib/dist-COeuceiv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/MarkdownRenderer-DoVbFpA6-Cj6PSy5i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/common-ui.es-DsyLvwIV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/common-ui.es-DsyLvwIV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/assets/dist-D4fpn-Cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/dist-GwWsrg82.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/dist-GwWsrg82.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/assets/index-D_Z-_zpu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/assets/index-D_Z-_zpu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.31

3 findings
HIGH New obfuscated file: dist/assets/index-CKWL4yvm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-CKWL4yvm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.30

3 findings
HIGH New obfuscated file: dist/assets/index-DF3SIdoO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DF3SIdoO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.29

3 findings
HIGH New obfuscated file: dist/assets/index-Cr_Q6ieW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-Cr_Q6ieW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.28

3 findings
HIGH New obfuscated file: dist/assets/index-DAcpxSe7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DAcpxSe7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.27

3 findings
HIGH New obfuscated file: dist/assets/index-C69g2NQ7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-C69g2NQ7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.26

3 findings
HIGH New obfuscated file: dist/assets/index-BwHrrJl0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-BwHrrJl0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.25

3 findings
HIGH New obfuscated file: dist/assets/index-zm234ck7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-zm234ck7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.24

3 findings
HIGH New obfuscated file: dist/assets/index-CbJoDxlk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-CbJoDxlk.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.23

3 findings
HIGH New obfuscated file: dist/assets/index-DDNsNEHf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DDNsNEHf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.22

3 findings
HIGH New obfuscated file: dist/assets/index-Cz0N_PW4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-Cz0N_PW4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.21

3 findings
HIGH New obfuscated file: dist/assets/index-B3b_lZhk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-B3b_lZhk.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.20

3 findings
HIGH New obfuscated file: dist/assets/index-DsPjKJpe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DsPjKJpe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.18

3 findings
HIGH New obfuscated file: dist/assets/index-PkV5qi5_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-PkV5qi5_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

3 findings
HIGH New obfuscated file: dist/assets/index-D3NtHgqQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-D3NtHgqQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

3 findings
HIGH New obfuscated file: dist/assets/index-BFPAwWXV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-BFPAwWXV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.15

3 findings
HIGH New obfuscated file: dist/assets/index-BFPAwWXV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-BFPAwWXV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.14

3 findings
HIGH New obfuscated file: dist/assets/index-DXjEpSH8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DXjEpSH8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.