← Home

ethjs-abi

12
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

silentcicero

Keywords

ethereumencodingdecoding

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file-transition:dist/ethjs-abi.min.js AI (source-diff): Webpack UMD bundle; module-loader/Buffer polyfill triggers heuristic, no real network+eval payload. ai
source-diff net-exec-file:dist/ethjs-abi.min.js AI (source-diff): Webpack UMD bundle of the library; net/eval hits are bundled deps, not a dropper. ai
source-diff source-size-tripled AI (source-diff): Size jump is the newly-committed dist bundle output, expected for this build. ai
dependencies unvetted-dep:ethjs-sha3 AI (dependencies): Canonical ethjs sibling by same publisher. ai
phantom-deps phantom-dep:hash.js AI (phantom-deps): Used transitively/in bundle; heuristic FP for minified build. ai

Versions (showing 12 of 12)

Version Deps Published
0.2.1 3 / 49
0.2.0 3 / 49
0.1.9 3 / 49
0.1.8 3 / 49
0.1.7 3 / 49
0.1.6 3 / 49
0.1.5 3 / 49
0.1.4 3 / 49
0.1.3 3 / 49
0.1.2 3 / 49
0.1.1 6 / 48
0.0.1 3 / 4

v0.2.0

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

2 findings
HIGH Modified file gained network + code execution: dist/ethjs-abi.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

2 findings
HIGH New file with network + code execution: dist/ethjs-abi.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.