@vue-skuilder/standalone-ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/assets/common-ui.es-DDvhbVBP.js | AI (source-diff): Vite bundler banner present; minified build output. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CQnBgFOT.js | AI (source-diff): Vite bundler entry chunk, standard build output. | ai | |
| source-diff | net-exec-file:dist/assets/dist-CDEq0Y3a.js | AI (source-diff): Bundled build output; no malicious network/exec behavior shown. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-CDEq0Y3a.js | AI (source-diff): Bundled commonJS shims (spark-md5 etc.), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DDvhbVBP.js | AI (source-diff): Standard bundled vue-router/network code, no dropper behavior evident. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-CS663iWK.js | AI (source-diff): Bundled router/framework code, no exfil behavior evident. | ai | |
| source-diff | net-exec-file:dist/assets/dist-DHtsWAkb.js | AI (source-diff): Bundled vendor code, no malicious network target found. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-CS663iWK.js | AI (source-diff): Vite bundle chunk; standard framework internals visible. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-DHtsWAkb.js | AI (source-diff): Bundled spark-md5/vendor libs, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Cib2NGQ_.js | AI (source-diff): Vite entrypoint bundle, standard module-preload polyfill code. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-mJg7wGOe.js | AI (source-diff): Vendored spark-md5/vue-router bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/dist-mJg7wGOe.js | AI (source-diff): No hostile network target identified; standard bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BTx-tECR.js | AI (source-diff): Vite entry bundle with modulepreload polyfill, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-CKDaicTB.js | AI (source-diff): Standard bundler fetch/eval patterns, no exfil destination. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-CKDaicTB.js | AI (source-diff): Vite bundle output with matching sourcemap. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DhLJkoaY.js | AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-CIWSsb1y.js | AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/dist-CIWSsb1y.js | AI (source-diff): Bundled vendor lib (spark-md5) plus module code, no malicious network target. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CIllvcxx.js | AI (source-diff): Vite/Rollup minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DhLJkoaY.js | AI (source-diff): Standard fetch/module-preload code in bundled Vue webapp, no exfiltration target. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DAD-mXog.js | AI (source-diff): Bundled fetch/dynamic-import polyfill pattern, no malicious target. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BYBX0RyH.js | AI (source-diff): Bundled spark-md5/vue-router deps, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BYBX0RyH.js | AI (source-diff): Bundled code, no exfil/dropper behavior evident. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Ch4dDCy5.js | AI (source-diff): Vite entry bundle, standard modulepreload polyfill. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DAD-mXog.js | AI (source-diff): Vite-bundled internal package output. | ai | |
| source-diff | obfuscated-file:dist/assets/index-9XwHN2NO.js | AI (source-diff): Vite entry bundle with module preload polyfill, standard build output. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-BFeiYXxe.js | AI (source-diff): Bundled fetch/module-loader polyfill code, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BKY5mgTZ.js | AI (source-diff): Bundled vendor code, no malicious network behavior found. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package metadata style, consistent across siblings, not spam. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-BFeiYXxe.js | AI (source-diff): Bundled common-ui asset, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BKY5mgTZ.js | AI (source-diff): Bundled vendor libs (spark-md5 etc), minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BA5iGova.js | AI (source-diff): Bundled lib code (spark-md5 etc.), no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-jVsEPQR7.js | AI (source-diff): Vite entry bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BA5iGova.js | AI (source-diff): Bundled output incl. spark-md5 lib, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DlYghJUY.js | AI (source-diff): Vite/Rollup bundled output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DlYghJUY.js | AI (source-diff): Standard modulepreload/fetch polyfill in bundled webapp, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-Dt1DQMFY.js | AI (source-diff): Vite-bundled vendor chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-CDhtG9sH.js | AI (source-diff): Vite-bundled vendor chunk (spark-md5 etc), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-Dt1DQMFY.js | AI (source-diff): Standard bundled fetch/dynamic import polyfill, no exfil behavior. | ai | |
| source-diff | net-exec-file:dist/assets/dist-CDhtG9sH.js | AI (source-diff): Standard bundled fetch/dynamic import polyfill, no exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DuGLD7Ss.js | AI (source-diff): Vite-bundled app entry chunk with modulepreload polyfill, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DsyLvwIV.js | AI (source-diff): Vite-bundled vue-router code, no malicious destination. | ai | |
| source-diff | net-exec-file:dist/assets/index-D_Z-_zpu.js | AI (source-diff): Vite bundler banner confirmed; main app bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D_Z-_zpu.js | AI (source-diff): Vite bundler banner confirmed; main app bundle. | ai | |
| source-diff | net-exec-file:dist/assets/dist-GwWsrg82.js | AI (source-diff): Bundled output, no concrete malicious behavior found. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-GwWsrg82.js | AI (source-diff): Same bundled build artifact pattern as sibling files. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-D4fpn-Cc.js | AI (source-diff): Standard rolldown/vite bundler preamble, minified moment.js etc. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DsyLvwIV.js | AI (source-diff): Vite bundler banner confirmed; standard build output. | ai | |
| source-diff | obfuscated-file:dist/assets/MarkdownRenderer-DoVbFpA6-Cj6PSy5i.js | AI (source-diff): Vite-bundled build output. | ai | |
| source-diff | net-exec-file:dist-lib/dist-COeuceiv.js | AI (source-diff): eval("require")("fs") is a standard bundler Node/browser interop shim. | ai | |
| source-diff | obfuscated-file:dist-lib/dist-COeuceiv.js | AI (source-diff): Bundled deps (spark-md5 etc.), minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist-lib/common-ui.es-CI3A9lXQ.js | AI (source-diff): Bundled Vue compiler code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist-lib/MarkdownRenderer-DoVbFpA6-DSu2Rt-U.js | AI (source-diff): Vite/rollup bundled Vue runtime, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CKWL4yvm.js | AI (source-diff): Vite-bundled webapp output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/index-CKWL4yvm.js | AI (source-diff): Standard fetch/module-preload code in bundled SPA, no malicious target. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-ibXGK5ti.js | AI (source-diff): Standard bundled router/fetch polyfill code, no exfil target. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-ibXGK5ti.js | AI (source-diff): Vite bundle banner confirms build output. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-DlSLFgY8.js | AI (source-diff): Bundled SparkMD5/vendor lib, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/dist-DlSLFgY8.js | AI (source-diff): Bundled vendor code; no malicious network destination. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CKXq4U_A.js | AI (source-diff): Vite entry chunk with modulepreload polyfill, standard bundler output. | ai | |
| source-diff | net-exec-file:dist/assets/index-DF3SIdoO.js | AI (source-diff): fetch()+eval-like patterns are vite/vue framework boilerplate, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DF3SIdoO.js | AI (source-diff): Vite bundle output, not true obfuscation; standard minified webapp asset. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DAcpxSe7.js | AI (source-diff): Standard Vite/Vue minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-DAcpxSe7.js | AI (source-diff): fetch used for module preloading in bundled Vite runtime, not exfil. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BwHrrJl0.js | AI (source-diff): Vite/Rollup bundled webapp output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-BwHrrJl0.js | AI (source-diff): Standard fetch-based modulepreload polyfill in bundled Vite output. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-D6tRtHge.js | AI (source-diff): Bundled vendor code (spark-md5), minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CDRvg5QJ.js | AI (source-diff): Standard Vite entry bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/dist-D6tRtHge.js | AI (source-diff): Bundled vendor library, no malicious network destination found. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-RbbhjMGz.js | AI (source-diff): Bundler module-preload polyfill fetch/import pattern, not exfil. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-RbbhjMGz.js | AI (source-diff): Bundled build output from monorepo shared package. | ai | |
| source-diff | net-exec-file:dist/assets/index-CbJoDxlk.js | AI (source-diff): Vite modulepreload fetch polyfill, standard bundle pattern, no malicious target. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CbJoDxlk.js | AI (source-diff): Vite bundle minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DDNsNEHf.js | AI (source-diff): Vite bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-DDNsNEHf.js | AI (source-diff): Standard fetch/preload code in Vite bundle. | ai | |
| source-diff | net-exec-file:dist/assets/index-DsPjKJpe.js | AI (source-diff): Standard Vite modulepreload/fetch polyfill, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DsPjKJpe.js | AI (source-diff): Vite-bundled webapp output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-DXjEpSH8.js | AI (source-diff): Standard vite modulepreload fetch logic, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DXjEpSH8.js | AI (source-diff): Vite bundle banner/minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/dist-SoAs4WNl.js | AI (source-diff): Bundled router/util code, no hostile network target. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Bg37fxGA.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-SoAs4WNl.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-CIGym5zn.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets/MarkdownRenderer-kStoDRNE-lsnQ9xYB.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-CIGym5zn.js | AI (source-diff): fetch+dynamic import is Vite's own module-preload polyfill, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/assets/index-Cr_Q6ieW.js | AI (source-diff): Bundler preload/fetch helpers, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Cr_Q6ieW.js | AI (source-diff): Standard Vite bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-C69g2NQ7.js | AI (source-diff): Standard Vite fetch/modulepreload polyfill in bundle, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-C69g2NQ7.js | AI (source-diff): Vite-bundled webapp output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-zm234ck7.js | AI (source-diff): Standard Vite bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-zm234ck7.js | AI (source-diff): fetch used for CSS/module preload polyfill, not exfil/dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Cz0N_PW4.js | AI (source-diff): Vite/webpack bundled webapp output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-Cz0N_PW4.js | AI (source-diff): Standard fetch+modulepreload polyfill in bundled front-end code, no malicious target. | ai | |
| source-diff | net-exec-file:dist/assets/index-B3b_lZhk.js | AI (source-diff): Vite modulepreload fetch polyfill, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-B3b_lZhk.js | AI (source-diff): Vite bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-PkV5qi5_.js | AI (source-diff): Vite build bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-PkV5qi5_.js | AI (source-diff): Standard Vite modulepreload fetch polyfill, not a dropper. | ai | |
| source-diff | net-exec-file:dist/assets/index-D3NtHgqQ.js | AI (source-diff): Standard Vite modulepreload fetch logic, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D3NtHgqQ.js | AI (source-diff): Vite-bundled webapp output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-BFPAwWXV.js | AI (source-diff): Standard Vite modulepreload/fetch polyfill code, not dropper behavior. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org monorepo packages and well-known 'events' polyfill. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BFPAwWXV.js | AI (source-diff): Vite bundler output, not true obfuscation; no malicious behavior. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-_Nay4Hg9.js | AI (source-diff): Network calls and dynamic imports are normal Vite lazy-loading patterns in this UI bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/index-lmLOFur1.js | AI (source-diff): Standard Vite entry bundle with modulepreload polyfill; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/dist-DHzymw-6.js | AI (source-diff): Network + dynamic code patterns are Vite bundle artifacts, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-DHzymw-6.js | AI (source-diff): Standard Vite minified bundle; sample shows spark-md5 and known library code. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-_Nay4Hg9.js | AI (source-diff): Standard Vite minified bundle output for this package; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-BLg_8nr-.js | AI (source-diff): Network calls are vue-router fetch/preload polyfills; dynamic code is module loading, not malware. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BUyUeqxf.js | AI (source-diff): Vite webapp entry bundle; minification is expected for this package type. | ai | |
| source-diff | net-exec-file:dist/assets/dist-Dw3a5Op4.js | AI (source-diff): Same bundle; network/exec pattern is module loading infrastructure, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-Dw3a5Op4.js | AI (source-diff): Standard Vite minified bundle; identifiable as spark-md5 and project-specific exports. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-BLg_8nr-.js | AI (source-diff): Standard Vite minified bundle output for a Vue UI library; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-Bh7QiFa1.js | AI (source-diff): Network calls and dynamic imports are normal Vue SPA routing patterns (vue-router lazy loading). | ai | |
| source-diff | obfuscated-file:dist/assets/index-BOK-JsV6.js | AI (source-diff): Standard Vite minified entry bundle with __vite__mapDeps; legitimate build artifact. | ai | |
| source-diff | net-exec-file:dist/assets/dist--Dpfoemh.js | AI (source-diff): Network/dynamic patterns are standard bundled library code, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/dist--Dpfoemh.js | AI (source-diff): Standard Vite minified bundle; spark-md5 and other readable identifiers confirm legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-Bh7QiFa1.js | AI (source-diff): Standard Vite minified bundle output; readable identifiers confirm legitimate build artifact. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-B6UqZKxa.js | AI (source-diff): Network calls and dynamic imports are Vite lazy-loading patterns, not dropper behavior. | ai | |
| phantom-deps | phantom-dep:@vue-skuilder/courseware | AI (phantom-deps): Same-org monorepo dep bundled into dist output. | ai | |
| phantom-deps | phantom-dep:@vue-skuilder/common-ui | AI (phantom-deps): Same-org monorepo dep bundled into dist output. | ai | |
| phantom-deps | phantom-dep:@vue-skuilder/common | AI (phantom-deps): Same-org monorepo dep bundled into dist output. | ai | |
| phantom-deps | phantom-dep:@vue-skuilder/db | AI (phantom-deps): Same-org monorepo dep bundled into dist output. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Bundled into dist; router code visible in samples. | ai | |
| phantom-deps | phantom-dep:@mdi/font | AI (phantom-deps): Icon font asset dep; referenced in Vite config not source imports. | ai | |
| phantom-deps | phantom-dep:vuetify | AI (phantom-deps): UI framework bundled into dist; declared as dep for consumers. | ai | |
| phantom-deps | phantom-dep:events | AI (phantom-deps): Node events polyfill used via Vite config, not direct import. | ai | |
| phantom-deps | phantom-dep:pinia | AI (phantom-deps): Vue ecosystem peer dep bundled into dist; not directly imported in source but legitimately declared. | ai | |
| source-diff | obfuscated-file:dist/assets/index-5H45bc-8.js | AI (source-diff): Vite entry bundle with modulepreload polyfill; standard SPA build artifact. | ai | |
| source-diff | net-exec-file:dist/assets/dist-B6gIbmvQ.js | AI (source-diff): Same Vite bundle pattern; dynamic code execution is AMD/CJS interop shim, not malicious loader. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-B6gIbmvQ.js | AI (source-diff): Standard Vite-minified bundle; contains spark-md5 and project-specific exports, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-B6UqZKxa.js | AI (source-diff): Standard Vite-minified bundle output for a Vue SPA; source maps present, content is recognizable Vue/router code. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BoYWClge.js | AI (source-diff): Vite webapp bundle; network calls are application-level API calls. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-Dli7wjjJ.js | AI (source-diff): Vite webapp bundle; network calls are application-level API calls. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Di-iurxs.js | AI (source-diff): Standard Vite minified bundle output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BoYWClge.js | AI (source-diff): Standard Vite minified bundle output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-Dli7wjjJ.js | AI (source-diff): Standard Vite minified bundle output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-rJK7G7mT.js | AI (source-diff): Standard Vite minified bundle output for a Vue UI library. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-CglDOuwn.js | AI (source-diff): Standard Vite minified bundle output for a Vue UI library. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-CIp6hqfh.js | AI (source-diff): Standard Vite minified bundle output for a Vue UI library. | ai | |
| source-diff | net-exec-file:dist/assets/dist-CglDOuwn.js | AI (source-diff): Vite webapp bundle; network calls are application-level API calls, not malware. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-CIp6hqfh.js | AI (source-diff): Vite webapp bundle; network calls are application-level API calls, not malware. | ai | |
| source-diff | obfuscated-file:dist/assets/index-e8XolFvR.js | AI (source-diff): Vite bundle; same pattern as other dist assets. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BcZ1gsNX.js | AI (source-diff): Vite bundle; same pattern as other dist assets. | ai | |
| source-diff | obfuscated-file:dist-lib/dist-BP0_sJdJ.js | AI (source-diff): Vite bundle of @vue-skuilder/db and spark-md5; recognizable OSS code. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DfgaTZ4z.js | AI (source-diff): Vite-minified common-ui bundle with vue-router; standard build output. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BcZ1gsNX.js | AI (source-diff): Vite bundle; same pattern. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DfgaTZ4z.js | AI (source-diff): Same as dist-lib counterpart; Vite dynamic imports + Vue compiler. | ai | |
| source-diff | net-exec-file:dist-lib/dist-BP0_sJdJ.js | AI (source-diff): eval('require') is a standard Node env-detection pattern; network calls are PouchDB/fetch; not malicious. | ai | |
| source-diff | net-exec-file:dist-lib/common-ui.es-B8Tew0sr.js | AI (source-diff): Network calls are Vue dynamic imports (__vite__mapDeps); exec is Vue compiler; no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DQVvqecz.js | AI (source-diff): Network calls are Vue Router/fetch patterns in minified bundle; not dropper behavior. | ai | |
| source-diff | net-exec-file:dist-lib/questions.mjs | AI (source-diff): Network calls are app API patterns in minified ESM library build. | ai | |
| source-diff | obfuscated-file:dist-lib/questions.mjs | AI (source-diff): Rolldown ESM library build; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CgJHLYRy.js | AI (source-diff): Minified Vite bundle; consistent with this package's build output. | ai | |
| source-diff | net-exec-file:dist/assets/dist-D0Pw05KO.js | AI (source-diff): Network calls are standard app API calls in minified bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-D0Pw05KO.js | AI (source-diff): Minified Vite bundle with spark-md5 and app logic; no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DQVvqecz.js | AI (source-diff): Standard Vite minified bundle output; stable pattern for this UI package. | ai | |
| source-diff | obfuscated-file:dist-lib/dist-D3TZHmH5.js | AI (source-diff): Minified Vite bundle of open-source deps (spark-md5, etc.); expected for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in Vue reactivity proxy handlers; standard Vue 3 internals pattern. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval('require') is a standard esbuild/Vite CJS shim for Node.js fs detection; not user-controlled. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 22 new files are Vite build artifacts from newly added build:lib and build:webapp scripts. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Package now ships full Vite dist; size jump is structural, not injection. | ai | |
| source-diff | obfuscated-file:dist/assets/index-C6NB1IPv.js | AI (source-diff): Minified Vite webapp entry; expected build artifact. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-DCANvFNh.js | AI (source-diff): Minified Vite bundle; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/assets/dist-BC_KquM-.js | AI (source-diff): Same Vite bundle pattern; no malicious network behavior identified. | ai | |
| source-diff | obfuscated-file:dist/assets/dist-BC_KquM-.js | AI (source-diff): Minified Vite bundle; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/assets/common-ui.es-DxZNthuJ.js | AI (source-diff): Dynamic imports via __vite__mapDeps are standard Vite lazy-loading, not malware. | ai | |
| source-diff | obfuscated-file:dist/assets/common-ui.es-DxZNthuJ.js | AI (source-diff): Minified Vite webapp asset with vue-router and component code; expected. | ai | |
| source-diff | obfuscated-file:dist/assets/MarkdownRenderer-DoVbFpA6-DYVMsbBP.js | AI (source-diff): Minified Vite webapp asset; same Vue compiler code as lib build. | ai | |
| source-diff | obfuscated-file:dist-lib/MarkdownRenderer-DoVbFpA6-BjR5e6Al.js | AI (source-diff): Standard Vite/Vue bundled output; minification is expected for this build-output package. | ai | |
| source-diff | net-exec-file:dist-lib/questions.cjs.js | AI (source-diff): CJS bundle entry point; inline font data and standard Vue component code, not dropper. | ai | |
| source-diff | net-exec-file:dist-lib/dist-D3TZHmH5.js | AI (source-diff): eval('require') pattern is a known Vite/esbuild CJS shim for Node detection; not malicious. | ai | |
| source-diff | net-exec-file:dist-lib/common-ui.es-BndKNv1Z.js | AI (source-diff): Vite-bundled Vue app; network calls are fetch/XHR in Vue router/component code, not dropper behavior. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 0.2.16 | 10 / 9 | |
| 0.2.15 | 10 / 9 | |
| 0.2.14 | 10 / 9 | |
| 0.2.13 | 10 / 9 | |
| 0.2.12 | 10 / 9 | |
| 0.2.11 | 10 / 9 | |
| 0.2.10 | 10 / 9 | |
| 0.2.9 | 10 / 9 | |
| 0.2.8 | 10 / 9 | |
| 0.2.7 | 10 / 9 | |
| 0.2.5 | 10 / 9 | |
| 0.2.4 | 10 / 9 | |
| 0.2.3 | 10 / 9 | |
| 0.2.2 | 10 / 9 | |
| 0.2.1 | 10 / 9 | |
| 0.2.0 | 10 / 9 | |
| 0.1.40 | 10 / 9 | |
| 0.1.39 | 10 / 9 | |
| 0.1.38 | 10 / 9 | |
| 0.1.36 | 10 / 9 | |
| 0.1.35 | 10 / 9 | |
| 0.1.33 | 10 / 9 | |
| 0.1.31 | 10 / 9 | |
| 0.1.30 | 10 / 9 | |
| 0.1.29 | 10 / 9 | |
| 0.1.28 | 10 / 9 | |
| 0.1.27 | 10 / 9 | |
| 0.1.26 | 10 / 9 | |
| 0.1.25 | 10 / 9 | |
| 0.1.24 | 10 / 9 | |
| 0.1.23 | 10 / 9 | |
| 0.1.22 | 10 / 9 | |
| 0.1.21 | 10 / 9 | |
| 0.1.20 | 10 / 9 | |
| 0.1.18 | 10 / 9 | |
| 0.1.17 | 10 / 9 | |
| 0.1.16 | 10 / 9 | |
| 0.1.15 | 10 / 9 | |
| 0.1.14 | 10 / 9 | |
| 0.1.1 | 7 / 7 |
v0.2.16
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.15
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.14
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.13
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.12
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.33
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.31
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.30
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.29
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.28
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.27
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.26
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.25
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.24
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.23
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.22
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.21
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.20
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.18
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.17
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.15
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.14
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.