@xyo-network/chain-sdk
XYO Layer One SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost ganache RPC in e2e test spec, not a real remote raw-IP endpoint. | ai | |
| phantom-deps | phantom-dep:@xyo-network/account-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| phantom-deps | phantom-dep:@xyo-network/wallet-model | AI (phantom-deps): Same-org sibling package, likely type-only or re-export usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are standard OpenTelemetry/chalk packages, consistent with added telemetry features. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff spans many skipped npm versions consolidating sibling packages, not a sudden bundle injection. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth explained by merged chain-* submodules across skipped versions. | ai | |
| provenance | no-provenance | AI (provenance): Established xyo-network publisher; lack of provenance is consistent across their package ecosystem. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-rpc | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai | |
| dependencies | unvetted-dep:@xyo-network/chain-viewers | AI (dependencies): Same-org monorepo sibling package, pinned to matching version; not an independent risk. | ai |
Versions (showing 100 of 191)
| Version | Deps | Published |
|---|---|---|
| 4.5.4 | 18 / 20 | |
| 4.5.3 | 18 / 20 | |
| 4.5.2 | 18 / 21 | |
| 4.5.1 | 18 / 21 | |
| 4.5.0 | 18 / 21 | |
| 4.4.0 | 18 / 21 | |
| 4.3.2 | 18 / 21 | |
| 4.3.1 | 15 / 24 | |
| 4.3.0 | 15 / 24 | |
| 4.2.1 | 14 / 26 | |
| 4.1.0 | 14 / 26 | |
| 4.0.6 | 14 / 37 | |
| 4.0.5 | 14 / 37 | |
| 2.0.1 | 9 / 79 | |
| 2.0.0 | 9 / 79 | |
| 1.23.2 | 9 / 79 | |
| 1.23.0 | 9 / 79 | |
| 1.20.10 | 10 / 9 | |
| 1.20.8 | 10 / 9 | |
| 1.20.2 | 10 / 14 | |
| 1.19.16 | 10 / 16 | |
| 1.16.19 | 11 / 14 | |
| 1.16.13 | 9 / 14 | |
| 1.16.12 | 9 / 14 | |
| 1.16.11 | 9 / 14 | |
| 1.16.10 | 9 / 16 | |
| 1.16.9 | 10 / 16 | |
| 1.16.8 | 10 / 16 | |
| 1.16.7 | 10 / 16 | |
| 1.16.6 | 20 / 17 | |
| 1.16.5 | 21 / 16 | |
| 1.16.4 | 21 / 16 | |
| 1.16.3 | 21 / 16 | |
| 1.16.2 | 21 / 16 | |
| 1.16.1 | 21 / 16 | |
| 1.16.0 | 21 / 16 | |
| 1.15.28 | 21 / 16 | |
| 1.15.27 | 21 / 16 | |
| 1.15.26 | 21 / 16 | |
| 1.15.25 | 21 / 16 | |
| 1.15.24 | 21 / 16 | |
| 1.15.23 | 21 / 16 | |
| 1.15.22 | 21 / 16 | |
| 1.15.21 | 21 / 16 | |
| 1.15.20 | 21 / 16 | |
| 1.15.19 | 21 / 16 | |
| 1.15.18 | 21 / 16 | |
| 1.15.17 | 21 / 16 | |
| 1.15.16 | 21 / 16 | |
| 1.15.15 | 21 / 16 | |
| 1.15.14 | 21 / 16 | |
| 1.15.13 | 21 / 16 | |
| 1.15.12 | 21 / 16 | |
| 1.15.11 | 21 / 16 | |
| 1.15.10 | 21 / 16 | |
| 1.15.9 | 21 / 16 | |
| 1.15.8 | 21 / 16 | |
| 1.15.7 | 21 / 16 | |
| 1.15.6 | 21 / 16 | |
| 1.15.5 | 21 / 16 | |
| 1.15.4 | 21 / 16 | |
| 1.15.3 | 21 / 16 | |
| 1.15.2 | 21 / 16 | |
| 1.15.1 | 21 / 16 | |
| 1.15.0 | 21 / 16 | |
| 1.14.4 | 21 / 16 | |
| 1.14.3 | 21 / 16 | |
| 1.14.2 | 21 / 16 | |
| 1.14.1 | 21 / 16 | |
| 1.14.0 | 21 / 16 | |
| 1.13.0 | 21 / 16 | |
| 1.12.14 | 21 / 16 | |
| 1.12.13 | 21 / 16 | |
| 1.12.12 | 21 / 16 | |
| 1.12.11 | 21 / 16 | |
| 1.12.10 | 21 / 16 | |
| 1.12.9 | 21 / 16 | |
| 1.12.8 | 21 / 16 | |
| 1.12.7 | 21 / 16 | |
| 1.12.6 | 21 / 16 | |
| 1.12.5 | 21 / 16 | |
| 1.12.3 | 21 / 16 | |
| 1.12.1 | 21 / 16 | |
| 1.12.0 | 18 / 17 | |
| 1.11.0 | 18 / 17 | |
| 1.10.2 | 18 / 17 | |
| 1.10.1 | 18 / 17 | |
| 1.10.0 | 18 / 17 | |
| 1.9.0 | 18 / 17 | |
| 1.8.4 | 18 / 17 | |
| 1.8.3 | 18 / 17 | |
| 1.8.2 | 18 / 17 | |
| 1.8.1 | 18 / 17 | |
| 1.8.0 | 18 / 17 | |
| 1.7.20 | 18 / 17 | |
| 1.7.19 | 18 / 17 | |
| 1.7.18 | 18 / 17 | |
| 1.7.17 | 18 / 17 | |
| 1.7.16 | 18 / 17 | |
| 1.7.15 | 18 / 17 |
v4.5.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.4.0
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-18, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.2
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.2.1
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: atrouw.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.16
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-02-20, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.6
2 findings[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-11, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.5
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f279cc2c182457bd0b27a57a2207892cdb35dd07/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.4
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e637d1c037703f45810413ee2801314b58c5e95/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.3
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/033ba58b19b8595296bd11382aa084a1702965cc/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-10, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.2
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/78cfb466185cef026e1186499165233c1cc71cb0/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-10, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.1
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/00b2b9ad3597a656e0718635d401bade8c64ad0b/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-09, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca43e940ac4bda60cbe09348d41c7dcf6aac889d/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-08, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.28
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e4450e93b6d0ee13f32ef279489b5272eea97950/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.27
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/86ce1b9d8da1646462ad6889e0c1ebbf2523bc52/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-05, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.26
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0e3bf9ff7efad3a975fab60cd3dc7b3a38ff8e08/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-11-05, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.25
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/81d4973abbe9e78c961d2e5a31592566d9229970/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-11-01, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.24
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/2e9e937a1be1d8e95573b8d27bcd41e8cb9f8cbb/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.23
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7d641071ddd6b54102e54d3041e07a4e913aa821/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.22
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/d3236222ef93b62b74f5a32b679d47c778bb247c/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-10-29, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.21
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e1f825ae32f95061a42744ae7dbf022d7aef229f/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.20
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/697ef574f0fca09c4c64cfd1070e528b7be067d2/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.19
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7ab98adc64de3f98894eaaeb73a381d6175ae9e3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-10-24, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.18
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/eb236fd9589fe2a714db9b367f1daf3f62eb5c39/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.17
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6be99456e7db2d6106fed098934422165671e56e/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.16
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/6a2b1bb97c74433a5e8f8232af040dd763abfc20/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-23, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.15
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/5c361d9030efbdf34287a2af50f49d2edca4a41d/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.14
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3d66ac9109e11d2ce2a1601de6314e0ec37eb54e/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.13
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-22, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.12
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8de7ee2d44b34578dc9a3223fea891ab45fbc0a2/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-22, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.11
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/bb6d420dcc5c3fee050530b6a2d69a3cf6ff58cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/bb6d420dcc5c3fee050530b6a2d69a3cf6ff58cc/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/bb6d420dcc5c3fee050530b6a2d69a3cf6ff58cc/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/bb6d420dcc5c3fee050530b6a2d69a3cf6ff58cc/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-21, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.10
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/237d43d398071ba9f57b7b28d35d761d12bd6e30/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/237d43d398071ba9f57b7b28d35d761d12bd6e30/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/237d43d398071ba9f57b7b28d35d761d12bd6e30/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/237d43d398071ba9f57b7b28d35d761d12bd6e30/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.9
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b9114cf9a10b520723886152e731cc315f7f45e7/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b9114cf9a10b520723886152e731cc315f7f45e7/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b9114cf9a10b520723886152e731cc315f7f45e7/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b9114cf9a10b520723886152e731cc315f7f45e7/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-17, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.8
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b910d825f3f65a1a121591cce876a91d4687b767/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b910d825f3f65a1a121591cce876a91d4687b767/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b910d825f3f65a1a121591cce876a91d4687b767/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b910d825f3f65a1a121591cce876a91d4687b767/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.7
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/101805cf217875e042bb6f3bdc39b72884fd2f24/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/101805cf217875e042bb6f3bdc39b72884fd2f24/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/101805cf217875e042bb6f3bdc39b72884fd2f24/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/101805cf217875e042bb6f3bdc39b72884fd2f24/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.6
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb5dd04ece6e5ca65aeff2701030b93442758661/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb5dd04ece6e5ca65aeff2701030b93442758661/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb5dd04ece6e5ca65aeff2701030b93442758661/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb5dd04ece6e5ca65aeff2701030b93442758661/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-10-15, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.5
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3cedf3eb6f305525b9f6cb758220f61fb5125f11/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3cedf3eb6f305525b9f6cb758220f61fb5125f11/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3cedf3eb6f305525b9f6cb758220f61fb5125f11/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3cedf3eb6f305525b9f6cb758220f61fb5125f11/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.4
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/4cda8123b4a9a45d756b879e60ff448dd58ae201/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/4cda8123b4a9a45d756b879e60ff448dd58ae201/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/4cda8123b4a9a45d756b879e60ff448dd58ae201/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/4cda8123b4a9a45d756b879e60ff448dd58ae201/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-10-15, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.3
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b1533f83817c2b53864986383c79a42afecce3ca/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b1533f83817c2b53864986383c79a42afecce3ca/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b1533f83817c2b53864986383c79a42afecce3ca/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b1533f83817c2b53864986383c79a42afecce3ca/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.2
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3b1704cc828a4a0154de8fd0b46f41a79f9ecdc5/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3b1704cc828a4a0154de8fd0b46f41a79f9ecdc5/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3b1704cc828a4a0154de8fd0b46f41a79f9ecdc5/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3b1704cc828a4a0154de8fd0b46f41a79f9ecdc5/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-09-29, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.1
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3912efcf16b4a3b9766b32c90e338045f010e7fa/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3912efcf16b4a3b9766b32c90e338045f010e7fa/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3912efcf16b4a3b9766b32c90e338045f010e7fa/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3912efcf16b4a3b9766b32c90e338045f010e7fa/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-09-22, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.15.0
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e960b8ee182d5e3af9c1fcadbb665dff328787fc/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e960b8ee182d5e3af9c1fcadbb665dff328787fc/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e960b8ee182d5e3af9c1fcadbb665dff328787fc/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e960b8ee182d5e3af9c1fcadbb665dff328787fc/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.4
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/947d3afa137a59d3e78f8e8ebac01b8a2dc3638c/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/947d3afa137a59d3e78f8e8ebac01b8a2dc3638c/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/947d3afa137a59d3e78f8e8ebac01b8a2dc3638c/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/947d3afa137a59d3e78f8e8ebac01b8a2dc3638c/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-09-11, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.14.3
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fda8153d4b1b37773baae150c11a62c7c87e3649/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fda8153d4b1b37773baae150c11a62c7c87e3649/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fda8153d4b1b37773baae150c11a62c7c87e3649/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fda8153d4b1b37773baae150c11a62c7c87e3649/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.2
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8b050bcc8312d598047a724311ebc602ac6b2c78/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8b050bcc8312d598047a724311ebc602ac6b2c78/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8b050bcc8312d598047a724311ebc602ac6b2c78/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/8b050bcc8312d598047a724311ebc602ac6b2c78/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.1
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7862dcd7e5013067cf70673938d6ec26418b3085/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7862dcd7e5013067cf70673938d6ec26418b3085/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7862dcd7e5013067cf70673938d6ec26418b3085/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/7862dcd7e5013067cf70673938d6ec26418b3085/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.14.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/90d8a309472c41c2cd6ab4bf5ab6b52abca31859/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/90d8a309472c41c2cd6ab4bf5ab6b52abca31859/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/90d8a309472c41c2cd6ab4bf5ab6b52abca31859/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/90d8a309472c41c2cd6ab4bf5ab6b52abca31859/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.13.0
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fd9a03d7913a7abc330ce2881f14066481dec8b8/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fd9a03d7913a7abc330ce2881f14066481dec8b8/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fd9a03d7913a7abc330ce2881f14066481dec8b8/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fd9a03d7913a7abc330ce2881f14066481dec8b8/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.14
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/74e23b7170d55a72d95827c12380f3c8bb202880/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/74e23b7170d55a72d95827c12380f3c8bb202880/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/74e23b7170d55a72d95827c12380f3c8bb202880/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/74e23b7170d55a72d95827c12380f3c8bb202880/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.13
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e7cd822983f8b40eea3aeee99d0b451bc686b2fa/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e7cd822983f8b40eea3aeee99d0b451bc686b2fa/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e7cd822983f8b40eea3aeee99d0b451bc686b2fa/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/e7cd822983f8b40eea3aeee99d0b451bc686b2fa/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-25, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.12
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/df104619e7dfc4352ecdd3544f8463d7c3d3b26a/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/df104619e7dfc4352ecdd3544f8463d7c3d3b26a/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/df104619e7dfc4352ecdd3544f8463d7c3d3b26a/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/df104619e7dfc4352ecdd3544f8463d7c3d3b26a/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-22, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.11
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/aabc37ef8b73595d163a1c7537bac6bcd7681d1b/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/aabc37ef8b73595d163a1c7537bac6bcd7681d1b/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/aabc37ef8b73595d163a1c7537bac6bcd7681d1b/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/aabc37ef8b73595d163a1c7537bac6bcd7681d1b/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.10
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3c9ef49da916830a6f7c49305cb412d74bce5608/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3c9ef49da916830a6f7c49305cb412d74bce5608/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3c9ef49da916830a6f7c49305cb412d74bce5608/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3c9ef49da916830a6f7c49305cb412d74bce5608/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-22, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.9
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/32474948609606b0fb5eaeb3cb6b410ad76bd973/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/32474948609606b0fb5eaeb3cb6b410ad76bd973/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/32474948609606b0fb5eaeb3cb6b410ad76bd973/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/32474948609606b0fb5eaeb3cb6b410ad76bd973/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-22, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.8
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/1f59f12b22559b5104c49b2f6e5c8a05b85d654d/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/1f59f12b22559b5104c49b2f6e5c8a05b85d654d/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/1f59f12b22559b5104c49b2f6e5c8a05b85d654d/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/1f59f12b22559b5104c49b2f6e5c8a05b85d654d/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.7
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/487f962866b64cf628b0235f8ed7c793df4203e7/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/487f962866b64cf628b0235f8ed7c793df4203e7/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/487f962866b64cf628b0235f8ed7c793df4203e7/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/487f962866b64cf628b0235f8ed7c793df4203e7/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-22, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.6
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f40994472bc8f97bb9bce5426a53774c3645b6b9/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f40994472bc8f97bb9bce5426a53774c3645b6b9/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f40994472bc8f97bb9bce5426a53774c3645b6b9/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f40994472bc8f97bb9bce5426a53774c3645b6b9/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-18, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.5
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0f68a75086e59a6f8f30807bf5df06d56ff848f9/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0f68a75086e59a6f8f30807bf5df06d56ff848f9/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0f68a75086e59a6f8f30807bf5df06d56ff848f9/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/0f68a75086e59a6f8f30807bf5df06d56ff848f9/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.3
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/a29811fa2432b7ba2b64855c34200dd1112442e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/a29811fa2432b7ba2b64855c34200dd1112442e3/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/a29811fa2432b7ba2b64855c34200dd1112442e3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/a29811fa2432b7ba2b64855c34200dd1112442e3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2025-08-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.12.1
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02e519015abed513a36884d3b39e94a2100d855f/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02e519015abed513a36884d3b39e94a2100d855f/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02e519015abed513a36884d3b39e94a2100d855f/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02e519015abed513a36884d3b39e94a2100d855f/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e39dfb17d7cb0ca90fa0e0306d04548011550d9/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e39dfb17d7cb0ca90fa0e0306d04548011550d9/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e39dfb17d7cb0ca90fa0e0306d04548011550d9/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/3e39dfb17d7cb0ca90fa0e0306d04548011550d9/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-12, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.11.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c03a46ff2f8c0a00bcbfea54785279d989d4300c/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c03a46ff2f8c0a00bcbfea54785279d989d4300c/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c03a46ff2f8c0a00bcbfea54785279d989d4300c/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c03a46ff2f8c0a00bcbfea54785279d989d4300c/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-08, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.10.2
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c15b97997afcbfa29620665c5d0b36d178ddf463/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c15b97997afcbfa29620665c5d0b36d178ddf463/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c15b97997afcbfa29620665c5d0b36d178ddf463/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/c15b97997afcbfa29620665c5d0b36d178ddf463/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.1
5 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f560d9aa2ecd7b6f1238facc487e55c1d823d715/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f560d9aa2ecd7b6f1238facc487e55c1d823d715/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f560d9aa2ecd7b6f1238facc487e55c1d823d715/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/f560d9aa2ecd7b6f1238facc487e55c1d823d715/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/429008ffe7322b38e1f79806220704f80d7183eb/src/e2e/spec/EvmBlockRewardService.spec.ts#L55 53 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 54 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 55 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 56 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 57 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/429008ffe7322b38e1f79806220704f80d7183eb/src/e2e/spec/EvmBlockRewardService.spec.ts#L57 55 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 56 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 57 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 58 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 59 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/429008ffe7322b38e1f79806220704f80d7183eb/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/429008ffe7322b38e1f79806220704f80d7183eb/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-08-06, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.9.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b0e61e489861bd70268b184dca7a773a6e6b0141/src/e2e/spec/EvmBlockRewardService.spec.ts#L53 51 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 52 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 53 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 55 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b0e61e489861bd70268b184dca7a773a6e6b0141/src/e2e/spec/EvmBlockRewardService.spec.ts#L55 53 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 55 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 56 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 57 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b0e61e489861bd70268b184dca7a773a6e6b0141/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/b0e61e489861bd70268b184dca7a773a6e6b0141/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-30, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.4
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fe201b1d1e90883306aa1116b16d411b0d9ba357/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fe201b1d1e90883306aa1116b16d411b0d9ba357/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fe201b1d1e90883306aa1116b16d411b0d9ba357/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fe201b1d1e90883306aa1116b16d411b0d9ba357/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-29, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.3
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb2121e63c93fb63564423a28501ab4db03bfc4a/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb2121e63c93fb63564423a28501ab4db03bfc4a/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb2121e63c93fb63564423a28501ab4db03bfc4a/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb2121e63c93fb63564423a28501ab4db03bfc4a/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-29, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.2
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/34482be80841e88425341ddf97befd9b611e767b/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/34482be80841e88425341ddf97befd9b611e767b/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/34482be80841e88425341ddf97befd9b611e767b/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/34482be80841e88425341ddf97befd9b611e767b/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-28, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.1
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/734eeeaa87d829530dd92cd2aa7dad2d08f772ef/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/734eeeaa87d829530dd92cd2aa7dad2d08f772ef/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/734eeeaa87d829530dd92cd2aa7dad2d08f772ef/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/734eeeaa87d829530dd92cd2aa7dad2d08f772ef/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.8.0
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ece53a9054089e312f86a0afc061b0fb86dbb1d3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ece53a9054089e312f86a0afc061b0fb86dbb1d3/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ece53a9054089e312f86a0afc061b0fb86dbb1d3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ece53a9054089e312f86a0afc061b0fb86dbb1d3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-28, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.20
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb0028c61401750f5ac096c271f76a66b6e31f65/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 53 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb0028c61401750f5ac096c271f76a66b6e31f65/src/e2e/spec/EvmBlockRewardService.spec.ts#L56 54 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 56 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 57 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 58 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb0028c61401750f5ac096c271f76a66b6e31f65/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/fb0028c61401750f5ac096c271f76a66b6e31f65/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-28, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.19
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02a3cb59f9a04e5e2900e76bf54060b9858b8458/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02a3cb59f9a04e5e2900e76bf54060b9858b8458/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02a3cb59f9a04e5e2900e76bf54060b9858b8458/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/02a3cb59f9a04e5e2900e76bf54060b9858b8458/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (xyo) on 2025-07-25, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.18
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca08ea1242c024364c1fe86089b630c866838c8f/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca08ea1242c024364c1fe86089b630c866838c8f/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca08ea1242c024364c1fe86089b630c866838c8f/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/ca08ea1242c024364c1fe86089b630c866838c8f/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-24, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.17
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/28a3d940115c1ec7d8dbb7ef3e6761655c7bdd11/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/28a3d940115c1ec7d8dbb7ef3e6761655c7bdd11/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/28a3d940115c1ec7d8dbb7ef3e6761655c7bdd11/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/28a3d940115c1ec7d8dbb7ef3e6761655c7bdd11/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (joelbcarter) than the most recent previously approved version (jonesmac) on 2025-07-24, but joelbcarter is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.16
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/19be625102fbe3d71b0a9832581fd9900cc79532/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/19be625102fbe3d71b0a9832581fd9900cc79532/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/19be625102fbe3d71b0a9832581fd9900cc79532/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/19be625102fbe3d71b0a9832581fd9900cc79532/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-24, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.7.15
6 findingsHTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/27efc9b62b1af5a68d54f278191b2d548fd479a3/src/e2e/spec/EvmBlockRewardService.spec.ts#L52 50 | accountPerson = await walletPerson.derivePath("m/44'/60'/0'/0/0") 51 | accountPerson2 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/27efc9b62b1af5a68d54f278191b2d548fd479a3/src/e2e/spec/EvmBlockRewardService.spec.ts#L54 52 | provider = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 53 | ethWalletPerson = new Wallet(accountPerson.privateKey, provider) > 54 | provider2 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 55 | ethWalletPerson2 = new Wallet(accountPerson2.privateKey, provider2) 56 | const rewardsContract = await createChainRewardsContract(ethWalletPerson, genesisReward, getDefaultGasConfig())
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/27efc9b62b1af5a68d54f278191b2d548fd479a3/src/e2e/spec/EvmChainService.spec.ts#L51 49 | account0 = await walletPerson.derivePath("m/44'/60'/0'/0/0") 50 | account1 = await walletPerson.derivePath("m/44'/60'/0'/0/1") > 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337)
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/xylabs/xyo-chain/blob/27efc9b62b1af5a68d54f278191b2d548fd479a3/src/e2e/spec/EvmChainService.spec.ts#L53 51 | provider0 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 52 | ethWalletPerson0 = new Wallet(account0.privateKey, provider0) > 53 | provider1 = new JsonRpcProvider(`http://127.0.0.1:${ganachePort}`, 1337) 54 | ethWalletPerson1 = new Wallet(account1.privateKey, provider1) 55 | }, 20_000)
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2025-07-24, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.