← Home

ccxt

6
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

x84randomguy007

Keywords

algorithmicalgotradingaltcoinaltcoinsapiarbitragereal-timerealtimebacktestbacktestingbitcoinbotbtccnycoincoinscryptocryptocurrencycrypto currencycrypto marketcurrencycurrenciesdarkcoindashdigital currencydogedogecoine-commerceetcethetherethereumexchangeexchangeseurframeworkinvestinvestinginvestorlibrarylightlitecoinltcmarketmarket datamarketsmerchandisemerchantminimalohlcvorderorderbookorder bookpriceprice datapricefeedprivatepublicripplestrategytickertickerstoolkittradetradertradingusdvolumewebsocketwebsocketsweb socketweb socketswsxbtxrpzeczerocoin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff large-new-source-files AI (source-diff): New prediction-market exchange modules match added build scripts; legitimate feature expansion. ai
phantom-deps phantom-dep:undici AI (phantom-deps): Scan-truncation artifact on large monorepo; undici is a genuine ccxt dependency. ai
source-diff net-exec-file:dist/ccxt.browser.min.min.js AI (source-diff): rspack-bundled browser minified output; expected build artifact for this package. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws used by WebSocket/transpiled paths; stable FP for ccxt. ai
phantom-deps phantom-dep:@scure/bip32 AI (phantom-deps): crypto dep for wallet/key derivation; stable FP. ai
phantom-deps phantom-dep:@scure/bip39 AI (phantom-deps): crypto dep for wallet/key derivation; stable FP. ai
typosquat typosquat.levenshtein:next AI (typosquat): ccxt is a well-known crypto library, not a typosquat of next; Levenshtein match is coincidental. ai
install-scripts install-script:postinstall AI (install-scripts): Long-standing benign postinstall banner in canonical ccxt; provenance-attested. ai
typosquat typosquat.levenshtein:nuxt AI (typosquat): ccxt is a well-known crypto library, not a typosquat of nuxt; Levenshtein match is coincidental. ai
semgrep semgrep:shady-links-tlds AI (semgrep): bitbank.cc is a legitimate Japanese crypto exchange; .cc TLD is expected in ccxt exchange integrations. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in bundled ethers.js static dependency is standard ethers library code, not malicious. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode in bundled ethers.js utils is standard cryptographic utility, not payload hiding. ai
semgrep semgrep:new-function-constructor AI (semgrep): new Function() in zklink WASM glue code is standard WebAssembly JS binding pattern. ai

Versions (showing 6 of 6)

Version Deps Published
4.5.66 6 / 36
4.5.65 6 / 36
4.5.64 7 / 35
4.5.51 1 / 35
4.5.22 1 / 35
4.5.18 1 / 35

v4.5.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.65

2 findings
HIGH New file with network + code execution: dist/ccxt.browser.min.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.64

5 findings
HIGH Package has 'postinstall' script install-scripts

[Reject — re-review on republish] (prior reject: AI (install-scripts): Postinstall by an unknown publisher on an established package is a critical supply-chain risk signal.) Script: node postinstall.js

HIGH Phantom dependency: ws phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

HIGH Phantom dependency: @scure/bip32 phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

HIGH Phantom dependency: @scure/bip39 phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.5.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.