← Home

cesium

33
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

pjcozzikringmramatolilleysetfilijjspaceanalyticalgraphicsggetzlikangningjjhembdptrgagssvargas95cesiumcesiumgsadminsrothst1lukemckinstrymzschwartz5

Keywords

3Dwebglgeospatialmapglobe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:Build/Cesium/Workers/createPlaneOutlineGeometry.js AI (source-diff): Minified build output of Cesium's own geometry worker, not obfuscation. ai
source-diff obfuscated-file:Build/Cesium/Workers/createPlaneGeometry.js AI (source-diff): Minified build output of Cesium's own geometry worker, not obfuscation. ai
maintainer-change maintainer-added AI (maintainer-change): Known Cesium team maintainers added; publisher pjcozzi matches prior approved maintainer list. ai
source-diff net-exec-file:Source/ThirdParty/knockout-3.4.2.js AI (source-diff): Well-known third-party knockout.js library, not injected malware. ai
source-diff obfuscated-file:Build/Cesium/Workers/createFrustumOutlineGeometry.js AI (source-diff): Standard minified Cesium worker build output, not injected code. ai
source-diff obfuscated-file:Build/Cesium/Workers/createFrustumGeometry.js AI (source-diff): Standard minified Cesium worker build output, not injected code. ai
source-diff obfuscated-file:Source/Core/GoogleEarthEnterpriseMetadata.js AI (source-diff): New unminified feature source, long-line trigger false positive. ai
source-diff obfuscated-file:Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js AI (source-diff): Minified worker bundle, legit GEE feature addition. ai
source-diff obfuscated-file:Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js AI (source-diff): Minified worker bundle, legit GEE feature addition. ai
source-diff obfuscated-file:Source/Scene/GoogleEarthEnterpriseMapsProvider.js AI (source-diff): New unminified feature source, long-line trigger false positive. ai
maintainer-change maintainer-removed AI (maintainer-change): Publisher is known prior maintainer per provenance INFO note; not a takeover. ai
source-diff net-exec-file:Build/Cesium/Workers/transcodeCRNToDXT.js AI (source-diff): Same crunch worker file; no malicious network/exec behavior, just minified WASM-era JS. ai
source-diff net-exec-file:Source/ThirdParty/crunch.js AI (source-diff): Same crunch library source file, benign. ai
source-diff obfuscated-file:Source/ThirdParty/crunch.js AI (source-diff): Third-party crunch/crnlib source, documented and licensed, not malicious obfuscation. ai
source-diff net-exec-file:Build/CesiumUnminified/Workers/transcodeCRNToDXT.js AI (source-diff): Same crunch library file, benign. ai
source-diff obfuscated-file:Build/CesiumUnminified/Workers/transcodeCRNToDXT.js AI (source-diff): Same crunch library, unminified build variant. ai
source-diff obfuscated-file:Build/Cesium/Workers/transcodeCRNToDXT.js AI (source-diff): Emscripten-compiled crunch texture lib, long lines are build output not obfuscation. ai
source-diff obfuscated-file:Source/ThirdParty/earcut-2.1.1.js AI (source-diff): earcut is a legitimate minified third-party triangulation library, not malicious obfuscation. ai
semgrep semgrep:eval-usage AI (semgrep): Worker bootstrap shim pattern in bundled build output, not attacker-controlled input. ai
source-diff encoded-string-file:Build/Cesium/Cesium.js AI (source-diff): atob() of inline workers bundle; documented CesiumJS build artifact. ai
source-diff large-new-source-files AI (source-diff): Chunk-hashed worker files rotate names each release; stable for CesiumJS. ai
source-diff encoded-string-file:Build/CesiumUnminified/Cesium.js AI (source-diff): atob() of inline workers bundle; documented CesiumJS build artifact. ai
source-diff encoded-string-file:Build/CesiumUnminified/index.cjs AI (source-diff): Base64-encoded inline workers; standard CesiumJS build pattern. ai
source-diff encoded-string-file:Build/Cesium/index.cjs AI (source-diff): GLSL shader strings and minified build output; stable pattern for CesiumJS. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled KTX2 transcoder worker; standard pattern in Cesium's build output, not user-controlled input. ai
semgrep semgrep:dynamic-require AI (semgrep): Prod/dev conditional require in index.cjs is a well-known pattern; paths are static strings, not user input. ai

Versions (showing 33 of 33)

Version Deps Published
1.143.0 3 / 53
1.142.0 2 / 53
1.141.0 2 / 53
1.140.0 2 / 51
1.42.0 1 / 37
1.41.0 1 / 36
1.40.0 1 / 36
1.39.0 1 / 36
1.38.0 1 / 36
1.37.0 1 / 36
1.36.0 1 / 36
1.35.2 1 / 36
1.35.1 1 / 36
1.34.0 1 / 36
1.32.1 1 / 37
1.31.0 1 / 37
1.30.0 1 / 36
1.29.0 1 / 36
1.28.0 1 / 35
1.27.0 1 / 35
1.26.0 1 / 35
1.25.0 1 / 35
1.24.0 1 / 35
1.23.0 1 / 35
1.22.2 1 / 35
1.22.1 1 / 35
1.22.0 1 / 35
1.21.0 1 / 35
1.20.0 1 / 35
1.19.0 1 / 21
1.18.0 1 / 21
1.17.0 1 / 21
1.16.0 1 / 21

v1.143.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lukemckinstry → ggetz (on 2026-07-01, known maintainer) provenance

This version was published by a different npm account (ggetz) than the most recent previously approved version (lukemckinstry) on 2026-07-01, but ggetz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.42.0

11 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createPlaneGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createPlaneOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createVectorTileGeometries.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createVectorTilePolygons.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createVectorTilePolylines.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createVectorTilePoints.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/knockout-3.4.2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → analyticalgraphics (on 2018-02-01, known maintainer) provenance

This version was published by a different npm account (analyticalgraphics) than the most recent previously approved version (mramato) on 2018-02-01, but analyticalgraphics is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.41.0

7 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createPlaneGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createPlaneOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/knockout-3.4.2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → pjcozzi (on 2018-01-02, known maintainer) provenance

This version was published by a different npm account (pjcozzi) than the most recent previously approved version (mramato) on 2018-01-02, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.40.0

5 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/knockout-3.4.2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → tfili (on 2017-12-01, known maintainer) provenance

This version was published by a different npm account (tfili) than the most recent previously approved version (mramato) on 2017-12-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.39.0

4 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/knockout-3.4.2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.38.0

4 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/knockout-3.4.2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.37.0

4 findings
HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bagnell → lilleyse (on 2017-09-01, known maintainer) provenance

This version was published by a different npm account (lilleyse) than the most recent previously approved version (bagnell) on 2017-09-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.36.0

8 findings
HIGH New obfuscated file: Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/createFrustumOutlineGeometry.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Scene/GoogleEarthEnterpriseMapsProvider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Core/GoogleEarthEnterpriseMetadata.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bagnell → hpinkos (on 2017-08-01, known maintainer) provenance

This version was published by a different npm account (hpinkos) than the most recent previously approved version (bagnell) on 2017-08-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.35.2

6 findings
HIGH New obfuscated file: Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Scene/GoogleEarthEnterpriseMapsProvider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Core/GoogleEarthEnterpriseMetadata.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: bagnell → mramato (on 2017-07-11, known maintainer) provenance

This version was published by a different npm account (mramato) than the most recent previously approved version (bagnell) on 2017-07-11, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.35.1

12 findings
HIGH New obfuscated file: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Source/ThirdParty/crunch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/crunch.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Scene/GoogleEarthEnterpriseMapsProvider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Core/GoogleEarthEnterpriseMetadata.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hpinkos → mramato (on 2017-07-05, known maintainer) provenance

This version was published by a different npm account (mramato) than the most recent previously approved version (hpinkos) on 2017-07-05, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.34.0

11 findings
HIGH New obfuscated file: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Source/ThirdParty/crunch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/crunch.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: Source/Core/GoogleEarthEnterpriseMetadata.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hpinkos → tfili (on 2017-06-01, known maintainer) provenance

This version was published by a different npm account (tfili) than the most recent previously approved version (hpinkos) on 2017-06-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.32.1

8 findings
HIGH New obfuscated file: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Source/ThirdParty/crunch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/crunch.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hpinkos → bagnell (on 2017-04-03, known maintainer) provenance

This version was published by a different npm account (bagnell) than the most recent previously approved version (hpinkos) on 2017-04-03, but bagnell is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.31.0

8 findings
HIGH New obfuscated file: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/Cesium/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Build/CesiumUnminified/Workers/transcodeCRNToDXT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: Source/ThirdParty/crunch.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: Source/ThirdParty/crunch.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pjcozzi → lilleyse (on 2017-03-01, known maintainer) provenance

This version was published by a different npm account (lilleyse) than the most recent previously approved version (pjcozzi) on 2017-03-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.30.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pjcozzi → hpinkos (on 2017-02-01, known maintainer) provenance

This version was published by a different npm account (hpinkos) than the most recent previously approved version (pjcozzi) on 2017-02-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.29.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → pjcozzi (on 2017-01-02, known maintainer) provenance

This version was published by a different npm account (pjcozzi) than the most recent previously approved version (mramato) on 2017-01-02, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.28.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → tfili (on 2016-12-01, known maintainer) provenance

This version was published by a different npm account (tfili) than the most recent previously approved version (mramato) on 2016-12-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.27.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lilleyse → mramato (on 2016-11-01, known maintainer) provenance

This version was published by a different npm account (mramato) than the most recent previously approved version (lilleyse) on 2016-11-01, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.26.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lilleyse → bagnell (on 2016-10-03, known maintainer) provenance

This version was published by a different npm account (bagnell) than the most recent previously approved version (lilleyse) on 2016-10-03, but bagnell is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.25.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → lilleyse (on 2016-09-01, known maintainer) provenance

This version was published by a different npm account (lilleyse) than the most recent previously approved version (mramato) on 2016-09-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.24.0

3 findings
HIGH New obfuscated file: Source/ThirdParty/earcut-2.1.1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mramato → hpinkos (on 2016-08-01, known maintainer) provenance

This version was published by a different npm account (hpinkos) than the most recent previously approved version (mramato) on 2016-08-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.23.0

3 findings
HIGH New obfuscated file: Source/ThirdParty/earcut-2.1.1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tfili → pjcozzi (on 2016-07-01, known maintainer) provenance

This version was published by a different npm account (pjcozzi) than the most recent previously approved version (tfili) on 2016-07-01, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.22.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tfili → mramato (on 2016-06-14, known maintainer) provenance

This version was published by a different npm account (mramato) than the most recent previously approved version (tfili) on 2016-06-14, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.22.1

2 findings
MEDIUM Publisher changed: analyticalgraphicsinc → tfili (on 2016-06-13, unremoved on npm for 3693d) provenance

This version was published by a different npm account (tfili) than the most recent previously approved version (analyticalgraphicsinc) on 2016-06-13. It has since remained available on npm for 3693 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.0

2 findings
MEDIUM Publisher changed: analyticalgraphicsinc → tfili (on 2016-06-01, unremoved on npm for 3705d) provenance

This version was published by a different npm account (tfili) than the most recent previously approved version (analyticalgraphicsinc) on 2016-06-01. It has since remained available on npm for 3705 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.