@xyo-network/chain-sdk
XYO Layer One SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost ganache RPC in e2e test spec, not a real remote raw-IP endpoint. | ai | |
| phantom-deps | phantom-dep:@xyo-network/account-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| phantom-deps | phantom-dep:@xyo-network/wallet-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are standard OpenTelemetry/chalk packages, consistent with added telemetry features. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff spans many skipped npm versions consolidating sibling packages, not a sudden bundle injection. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth explained by merged chain-* submodules across skipped versions. | ai | |
| provenance | no-provenance | AI (provenance): Established xyo-network publisher; lack of provenance is consistent across their package ecosystem. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-rpc | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-viewers | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai |
Versions (showing 51 of 191)
| Version | Deps | Published |
|---|---|---|
| 4.5.4 | 18 / 20 | |
| 4.5.3 | 18 / 20 | |
| 4.5.2 | 18 / 21 | |
| 4.5.1 | 18 / 21 | |
| 4.5.0 | 18 / 21 | |
| 4.4.0 | 18 / 21 | |
| 4.3.2 | 18 / 21 | |
| 4.3.1 | 15 / 24 | |
| 4.3.0 | 15 / 24 | |
| 4.2.1 | 14 / 26 | |
| 4.1.0 | 14 / 26 | |
| 4.0.6 | 14 / 37 | |
| 4.0.5 | 14 / 37 | |
| 2.0.1 | 9 / 79 | |
| 2.0.0 | 9 / 79 | |
| 1.23.2 | 9 / 79 | |
| 1.23.0 | 9 / 79 | |
| 1.20.10 | 10 / 9 | |
| 1.20.8 | 10 / 9 | |
| 1.20.2 | 10 / 14 | |
| 1.19.16 | 10 / 16 | |
| 1.16.19 | 11 / 14 | |
| 1.16.13 | 9 / 14 | |
| 1.16.12 | 9 / 14 | |
| 1.16.11 | 9 / 14 | |
| 1.16.10 | 9 / 16 | |
| 1.16.9 | 10 / 16 | |
| 1.16.8 | 10 / 16 | |
| 1.16.7 | 10 / 16 | |
| 1.16.6 | 20 / 17 | |
| 1.16.5 | 21 / 16 | |
| 1.16.4 | 21 / 16 | |
| 1.16.3 | 21 / 16 | |
| 1.16.2 | 21 / 16 | |
| 1.16.1 | 21 / 16 | |
| 1.16.0 | 21 / 16 | |
| 1.15.28 | 21 / 16 | |
| 1.15.27 | 21 / 16 | |
| 1.15.26 | 21 / 16 | |
| 1.15.25 | 21 / 16 | |
| 1.15.24 | 21 / 16 | |
| 1.15.23 | 21 / 16 | |
| 1.15.22 | 21 / 16 | |
| 1.15.21 | 21 / 16 | |
| 1.15.20 | 21 / 16 | |
| 1.15.19 | 21 / 16 | |
| 1.15.18 | 21 / 16 | |
| 1.15.17 | 21 / 16 | |
| 1.15.16 | 21 / 16 | |
| 1.15.15 | 21 / 16 | |
| 1.15.14 | 21 / 16 |
v4.5.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-18, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-02-20, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-11, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.5
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.4
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.3
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.2
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-10, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.1
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-09, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-08, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.28
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.27
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-05, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.26
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-05, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.25
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-01, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.24
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.23
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.22
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-10-29, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.21
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.20
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.19
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-10-24, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.18
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.17
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.16
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.15
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.14
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.