← Home

promptfoo

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sklein12mdangeloianwjustinbeckwithfaizanminhas

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:child-process-import AI (semgrep): Python assertion execution feature; intrinsic to tool's eval functionality. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-specified local config file by extension; standard CLI pattern. ai
semgrep semgrep:new-function-constructor AI (semgrep): Documented custom-eval assertion feature, expected user-controlled code execution. ai
source-diff net-exec-file:dist/src/aws-DXcdBGfv.cjs AI (source-diff): Bundled AWS Bedrock provider; network+require is core to the tool's provider integrations. ai
source-diff net-exec-file:dist/src/providers-lmV8J0jR.cjs AI (source-diff): Bundled providers module; net+exec inherent to eval provider integrations. ai
source-diff obfuscated-file:dist/src/providers-lmV8J0jR.cjs AI (source-diff): Minified bundler output, not true obfuscation; matches package build. ai
source-diff obfuscated-file:dist/src/providers-DtkVivDo.cjs AI (source-diff): tsdown-minified provider bundle; long lines are build output not obfuscation. ai
source-diff net-exec-file:dist/src/providers-DtkVivDo.cjs AI (source-diff): Bundled provider module; network+exec expected for an LLM provider layer. ai
source-diff net-exec-file:dist/src/app/assets/index-FpA-mwjL.js AI (source-diff): Bundled front-end app code; benign fetch/render, not a loader. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-B3p8MQbf.js AI (source-diff): MUI-X vendor bundle; standard UI code. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-C99j8ebS.js AI (source-diff): Minified source-map-support vendor bundle. ai
source-diff obfuscated-file:dist/src/app/assets/index-FpA-mwjL.js AI (source-diff): Vite-bundled SPA asset; minified not obfuscated. ai
source-diff net-exec-file:dist/src/providers-CgKOSgTR.cjs AI (source-diff): Provider bundle legitimately makes network calls to LLM APIs; benign for this package. ai
source-diff obfuscated-file:dist/src/providers-CgKOSgTR.cjs AI (source-diff): Minified bundler output (long lines), not true obfuscation; stable across releases. ai
source-diff obfuscated-file:dist/src/providers-CpUrPa8s.cjs AI (source-diff): tsdown-minified build output, long lines are bundling not obfuscation. ai
source-diff net-exec-file:dist/src/providers-CpUrPa8s.cjs AI (source-diff): Bundled providers module; net+exec expected for provider integrations. ai
source-diff net-exec-file:dist/src/providers-DHbjzW2e.cjs AI (source-diff): Bundled provider module; long lines are build minification. ai
source-diff obfuscated-file:dist/src/providers-DHbjzW2e.cjs AI (source-diff): Minified tsdown build output, not obfuscation. ai
source-diff net-exec-file:dist/src/providers-BtzUfbxZ.cjs AI (source-diff): Bundled provider module; net+exec expected for eval provider execution. ai
source-diff obfuscated-file:dist/src/providers-BtzUfbxZ.cjs AI (source-diff): Minified tsdown bundle, not obfuscation; long lines are build artifacts. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-CEw_IGAd.js AI (source-diff): Minified source-map-support vendor bundle. ai
source-diff net-exec-file:dist/src/app/assets/index-DcG0DpZ5.js AI (source-diff): Bundled browser app; net+exec are normal SPA patterns, no hostile target. ai
source-diff obfuscated-file:dist/src/app/assets/index-DcG0DpZ5.js AI (source-diff): Vite-bundled React frontend asset; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/providers-D3WAfYou.cjs AI (source-diff): Minified bundler output, not true obfuscation; stable for this build pipeline. ai
source-diff net-exec-file:dist/src/providers-D3WAfYou.cjs AI (source-diff): Provider bundle legitimately makes network + exec calls; core function of the tool. ai
source-diff net-exec-file:dist/src/providers-4g9A4cGL.cjs AI (source-diff): Bundled provider module; minified build output, no true obfuscation signature. ai
source-diff obfuscated-file:dist/src/providers-4g9A4cGL.cjs AI (source-diff): tsdown-minified dist, long lines are build output not obfuscation. ai
source-diff obfuscated-file:dist/src/providers-BMeR_hLP.cjs AI (source-diff): Minified bundler output, not obfuscation; stable for this build pipeline. ai
source-diff net-exec-file:dist/src/providers-BMeR_hLP.cjs AI (source-diff): Bundled provider module; network+exec are core to LLM provider integrations. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-CVIuR1ht.js AI (source-diff): Minified source-map-support vendor chunk. ai
source-diff net-exec-file:dist/src/app/assets/index-CXp6Lh_8.js AI (source-diff): Bundled React/MUI app chunk; network+eval patterns are library code, not a dropper. ai
source-diff obfuscated-file:dist/src/app/assets/index-CXp6Lh_8.js AI (source-diff): Vite-bundled frontend chunk; minified build output, regenerated each release. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-CQ-TY82X.js AI (source-diff): Bundled source-map-support lib; minified vendor code. ai
source-diff obfuscated-file:dist/src/app/assets/index-C5kuLdph.js AI (source-diff): Vite-bundled SPA asset; minified build output, regenerated each release. ai
source-diff net-exec-file:dist/src/app/assets/index-C5kuLdph.js AI (source-diff): Bundled React app runtime, not a loader; benign for this package. ai
source-diff net-exec-file:dist/src/app/assets/index-DvnJzB2w.js AI (source-diff): Webapp bundle with normal fetch/dynamic-import; not a dropper. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-BmvzFAhR.js AI (source-diff): Minified source-map-support vendor bundle. ai
source-diff obfuscated-file:dist/src/app/assets/index-DvnJzB2w.js AI (source-diff): Vite-bundled frontend asset; minified build output, regenerates each release. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-vA4qspBa.js AI (source-diff): MUI-X vendor bundle; benign minified build output. ai
source-diff obfuscated-file:dist/src/providers-DmCBX83O.cjs AI (source-diff): Minified tsdown bundle output, not obfuscation; regenerated per release. ai
source-diff net-exec-file:dist/src/providers-DmCBX83O.cjs AI (source-diff): Provider bundle legitimately makes network+exec calls; build artifact. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-1v4oeb7P.js AI (source-diff): Bundled source-map-support vendor chunk, minified build output. ai
source-diff obfuscated-file:dist/src/app/assets/index-eJ2lMe94.js AI (source-diff): Vite-bundled web UI output, minified not obfuscated. ai
source-diff net-exec-file:dist/src/app/assets/index-eJ2lMe94.js AI (source-diff): Bundled SPA with fetch+dynamic import; benign vite build artifact. ai
source-diff net-exec-file:dist/src/providers-CFAJHysk.cjs AI (source-diff): Bundled provider module; network+exec expected for LLM provider integrations. ai
source-diff obfuscated-file:dist/src/providers-BNk2AdyA.cjs AI (source-diff): tsdown/rollup minified bundle, not obfuscation; stable build output. ai
source-diff net-exec-file:dist/src/providers-BNk2AdyA.cjs AI (source-diff): Bundled provider module; network+exec inherent to provider integrations. ai
source-diff net-exec-file:dist/src/app/assets/index-CDCJWS66.js AI (source-diff): Bundled React app entry; import/fetch machinery, no hostile target. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-BPdSsBdq.js AI (source-diff): Bundled source-map-support base64 VLQ codec; benign minified vendor code. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-B285qkCy.js AI (source-diff): Bundled MUI-X DataGrid vendor chunk; benign build output. ai
source-diff obfuscated-file:dist/src/app/assets/index-CDCJWS66.js AI (source-diff): Vite-bundled web UI asset; minified not obfuscated, stable per release. ai
source-diff net-exec-file:dist/src/providers-CS54SV62.cjs AI (source-diff): Bundled provider modules calling LLM APIs; expected behavior. ai
source-diff obfuscated-file:dist/src/data-DF-FvXLM.cjs AI (source-diff): Bundled redteam prompt-injection dataset, long lines are JSON strings; stable for this package. ai
source-diff obfuscated-file:dist/src/providers-BNKVY53V.cjs AI (source-diff): tsdown-minified provider bundle, not true obfuscation. ai
source-diff net-exec-file:dist/src/providers-BNKVY53V.cjs AI (source-diff): Bundled provider module; network calls are the package's core function. ai
source-diff net-exec-file:dist/src/providers-CFu-TZl-.cjs AI (source-diff): Bundled provider module; network+exec expected for provider execution. ai
source-diff obfuscated-file:dist/src/providers-CFu-TZl-.cjs AI (source-diff): Minified tsdown build output, not obfuscation; stable for this package's dist. ai
source-diff net-exec-file:dist/src/providers-BWoVY_Wz.cjs AI (source-diff): Bundled providers module; network+exec inherent to LLM provider integrations. ai
source-diff obfuscated-file:dist/src/providers-BWoVY_Wz.cjs AI (source-diff): Bundled/minified provider output, not true obfuscation. ai
source-diff net-exec-file:dist/src/providers-WnAfnzLf.cjs AI (source-diff): Bundled provider module of an LLM eval toolkit; network calls to LLM APIs are its core function. ai
source-diff obfuscated-file:dist/src/providers-CScd1wN6.cjs AI (source-diff): tsdown-minified build output, not obfuscation. ai
source-diff net-exec-file:dist/src/providers-CScd1wN6.cjs AI (source-diff): Bundled provider module; network calls are the package's stated function. ai
source-diff obfuscated-file:dist/src/providers-BF4aullZ.cjs AI (source-diff): Minified bundler output, not true obfuscation. ai
source-diff net-exec-file:dist/src/providers-BF4aullZ.cjs AI (source-diff): Bundled providers module; network+exec is inherent to an LLM-provider toolkit. ai
source-diff net-exec-file:dist/src/app/assets/index-DifT6VGT.js AI (source-diff): Bundled React app chunk; net+exec is normal SPA runtime, no hostile destination. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-Bnh0UQ2S.js AI (source-diff): Bundled source-map-support library; minified vite chunk. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-C2xF-yiO.js AI (source-diff): Bundled MUI-X vendor chunk; icon/component code, benign build output. ai
source-diff obfuscated-file:dist/src/app/assets/index-DifT6VGT.js AI (source-diff): Vite-bundled web UI output with visible bundler banner; minified not obfuscated. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-C0Zq2q0Y.js AI (source-diff): Bundled MUI-X vendor chunk; benign build output. ai
source-diff net-exec-file:dist/src/app/assets/index-Dn6NT1A2.js AI (source-diff): Bundled React app entry; net+exec are framework code, not a dropper. ai
source-diff obfuscated-file:dist/src/app/assets/index-Dn6NT1A2.js AI (source-diff): Vite-bundled web-app entry; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-XzfnsDIg.js AI (source-diff): Minified source-map-support vendor bundle. ai
install-scripts install-script:postinstall AI (install-scripts): Guarded hooks:install runs only in a .git checkout; no-op for consumers. ai
source-diff obfuscated-file:dist/src/providers-Bz0U4NGd.cjs AI (source-diff): Minified tsdown build output, not obfuscation; stable for this bundled package. ai
source-diff obfuscated-file:dist/src/providers-Ce2-tX4F.cjs AI (source-diff): Minified tsdown bundle output, not obfuscation. ai
source-diff net-exec-file:dist/src/providers-Ce2-tX4F.cjs AI (source-diff): Bundled provider registry; network+exec expected in an LLM eval tool. ai
source-diff net-exec-file:dist/src/providers-DEJW_Mce.cjs AI (source-diff): Bundled provider module; network+exec are core to the LLM provider layer. ai
source-diff obfuscated-file:dist/src/providers-DEJW_Mce.cjs AI (source-diff): tsdown-minified provider bundle; long lines are build output, no obfuscation signature. ai
source-diff net-exec-file:dist/src/providers-D1lUSO6m.cjs AI (source-diff): Bundled providers module; network+exec expected for an LLM provider toolkit. ai
source-diff obfuscated-file:dist/src/providers-D1lUSO6m.cjs AI (source-diff): Minified tsdown bundle, long lines are build output not obfuscation. ai
source-diff net-exec-file:dist/src/providers-BuFfPRsl.cjs AI (source-diff): Bundled provider module; network+exec expected for LLM eval tool. ai
source-diff obfuscated-file:dist/src/providers-BuFfPRsl.cjs AI (source-diff): Minified bundler output, not obfuscation; stable for this build pipeline. ai
source-diff net-exec-file:dist/src/providers-CbcT30KA.cjs AI (source-diff): Provider bundle; network+exec expected for LLM provider dispatch. ai
source-diff obfuscated-file:dist/src/providers-CbcT30KA.cjs AI (source-diff): tsdown bundle output (long lines), not true obfuscation. ai
source-diff obfuscated-file:dist/src/providers-7NldzwUW.cjs AI (source-diff): Minified bundler output, not obfuscation; recurs every build. ai
source-diff net-exec-file:dist/src/providers-7NldzwUW.cjs AI (source-diff): Bundled providers module; network+exec expected for LLM provider integrations. ai
source-diff obfuscated-file:dist/src/providers-Bp36xEIQ.cjs AI (source-diff): tsdown-bundled minified provider module, not true obfuscation. ai
source-diff net-exec-file:dist/src/providers-Bp36xEIQ.cjs AI (source-diff): Bundled provider module; network+exec are core to an LLM eval tool. ai
source-diff obfuscated-file:dist/src/providers-CvAgCuKp.cjs AI (source-diff): Minified tsdown bundle, not obfuscation; long lines are build output. ai
source-diff net-exec-file:dist/src/providers-CvAgCuKp.cjs AI (source-diff): Bundled provider module; network+exec inherent to a multi-provider LLM tool. ai
source-diff net-exec-file:dist/src/app/assets/index-DTy7aidn.js AI (source-diff): Bundled frontend SPA; net+exec is normal minified React app code. ai
source-diff obfuscated-file:dist/src/app/assets/index-DTy7aidn.js AI (source-diff): Vite-bundled minified webapp asset, not obfuscation. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-BiIeb3Ol.js AI (source-diff): Minified source-map-support lib in Vite bundle. ai
source-diff net-exec-file:dist/src/app/assets/vendor-mui-x-BZ0aDIR1.js AI (source-diff): Bundled MUI-X vendor chunk; benign minified output. ai
source-diff net-exec-file:dist/src/providers-CHa3rbfZ.cjs AI (source-diff): Bundled providers module; net+exec expected for provider integrations. ai
source-diff obfuscated-file:dist/src/providers-CHa3rbfZ.cjs AI (source-diff): Minified/bundled build output, not true obfuscation. ai
npm-metadata url-dep:rouge AI (npm-metadata): Long-standing immutably SHA-pinned ROUGE metric lib; unchanged across versions. ai
source-diff obfuscated-file:dist/src/providers-DQ428u-U.cjs AI (source-diff): Minified tsdown bundle output, not obfuscation; long lines are build artifacts. ai
source-diff net-exec-file:dist/src/providers-DQ428u-U.cjs AI (source-diff): Bundled provider module; network+exec inherent to provider integrations. ai
source-diff net-exec-file:dist/src/index.cjs AI (source-diff): Bundled dist entrypoint of a build tool; net+exec is expected for an LLM eval CLI. ai
source-diff obfuscated-file:dist/src/app/assets/index-iyBP4nBI.js AI (source-diff): Vite-bundled web UI, minified not obfuscated; recurs every release. ai
source-diff obfuscated-file:dist/src/app/assets/source-map-support-CSFI39ks.js AI (source-diff): Minified source-map-support library, benign bundle chunk. ai
source-diff net-exec-file:dist/src/app/assets/index-iyBP4nBI.js AI (source-diff): Bundled React app; network+exec patterns are normal SPA build output. ai
dependencies unvetted-dep:rouge AI (dependencies): rouge is a well-known NLP scoring lib used for eval metrics, fits stated purpose. ai
bogus-package bogus-package AI (bogus-package): Mature legitimate package; README/keyword heuristics are false positives here. ai
source-diff net-exec-file:dist/src/aws-Dao2vq-8.cjs AI (source-diff): Rolldown-bundled Bedrock provider; network+require are legit AWS/AI SDK usage, not a loader. ai
source-diff net-exec-file:dist/src/aws-DZ0G882T.cjs AI (source-diff): Bundled AWS Bedrock provider; network+exec is inherent to this LLM eval tool's purpose. ai
source-diff net-exec-file:dist/src/aws-D54hswwK.cjs AI (source-diff): Bundled AWS Bedrock provider; network+exec pattern is inherent to LLM provider SDK wrappers. ai
source-diff net-exec-file:dist/src/aws-B6z7Bp-y.cjs AI (source-diff): Bundled AWS Bedrock provider; network+exec is inherent to an LLM eval toolkit calling cloud APIs. ai
source-diff net-exec-file:dist/src/evalResult-BgL2HNJC.cjs AI (source-diff): Rolldown-bundled CJS chunk; network+require pattern is normal for bundled output. ai
source-diff large-new-source-files AI (source-diff): Bundler migration (rolldown) causes chunk filename churn; stable pattern for this package. ai
source-diff net-exec-file:dist/src/aws-CcirYqo_.cjs AI (source-diff): Rolldown-bundled CJS chunk for AWS Bedrock provider; network+require pattern is normal for this package. ai
phantom-deps phantom-dep:gcp-metadata AI (phantom-deps): Referenced in config/override context; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-base AI (phantom-deps): OTel SDK loaded via plugin pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@opencode-ai/sdk AI (phantom-deps): Optional provider integration; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): Type-only dep; used as framework-scoped type declaration, not a direct import. ai

Versions (showing 51 of 208)

View all versions
Version Deps Published
0.121.19 79 / 55
0.121.18 79 / 57
0.121.17 78 / 57
0.121.16 78 / 57
0.121.15 78 / 56
0.121.14 78 / 56
0.121.13 78 / 56
0.121.12 84 / 57
0.121.11 83 / 57
0.121.10 83 / 57
0.121.9 85 / 58
0.121.8 85 / 58
0.121.7 85 / 58
0.121.5 85 / 57
0.121.4 85 / 57
0.121.3 85 / 58
0.121.2 85 / 58
0.121.1 84 / 59
0.120.27 84 / 59
0.120.26 84 / 59
0.120.25 84 / 59
0.120.24 84 / 59
0.120.23 84 / 59
0.120.22 84 / 59
0.120.21 84 / 59
0.120.20 84 / 59
0.120.19 84 / 59
0.120.18 84 / 59
0.120.17 85 / 58
0.120.16 85 / 58
0.120.15 85 / 57
0.120.14 83 / 57
0.120.13 83 / 57
0.120.12 82 / 56
0.120.11 82 / 67
0.120.10 82 / 67
0.120.8 82 / 67
0.120.7 82 / 67
0.120.6 82 / 67
0.120.5 76 / 68
0.120.4 75 / 68
0.120.3 74 / 68
0.120.2 74 / 68
0.120.1 73 / 68
0.120.0 73 / 68
0.119.14 73 / 75
0.119.13 73 / 74
0.119.12 73 / 73
0.119.11 73 / 73
0.119.10 73 / 73
0.119.9 73 / 74

v0.121.19

2 findings
HIGH New file with network + code execution: dist/src/aws-DXcdBGfv.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.121.18

2 findings
HIGH New file with network + code execution: dist/src/aws-Dao2vq-8.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.121.3

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CScd1wN6.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CScd1wN6.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-03-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.121.2

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CgKOSgTR.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CgKOSgTR.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.121.1

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CFu-TZl-.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CFu-TZl-.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-03-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.27

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-DHbjzW2e.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-DHbjzW2e.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-03-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.26

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BNKVY53V.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BNKVY53V.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-03-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.25

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CpUrPa8s.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CpUrPa8s.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-02-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.24

6 findings
HIGH Package has 'postinstall' script install-scripts

Script: [ -d .git ] && npm run hooks:install || true

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BWoVY_Wz.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BWoVY_Wz.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-02-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.23

6 findings
HIGH Package has 'postinstall' script install-scripts

Script: [ -d .git ] && npm run hooks:install || true

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BF4aullZ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BF4aullZ.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-02-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.22

6 findings
HIGH Package has 'postinstall' script install-scripts

Script: [ -d .git ] && npm run hooks:install || true

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-lmV8J0jR.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-lmV8J0jR.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-02-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.21

6 findings
HIGH Package has 'postinstall' script install-scripts

Script: [ -d .git ] && npm run hooks:install || true

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-Bz0U4NGd.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-Bz0U4NGd.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-02-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.20

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-Ce2-tX4F.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-Ce2-tX4F.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-29, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.19

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-DEJW_Mce.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-DEJW_Mce.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.18

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-DtkVivDo.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-DtkVivDo.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.17

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-D3WAfYou.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-D3WAfYou.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.16

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-4g9A4cGL.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-4g9A4cGL.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.15

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-D1lUSO6m.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-D1lUSO6m.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.14

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BtzUfbxZ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BtzUfbxZ.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.13

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CbcT30KA.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CbcT30KA.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.12

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BNk2AdyA.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BNk2AdyA.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.11

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BuFfPRsl.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BuFfPRsl.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.10

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-7NldzwUW.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-7NldzwUW.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2026-01-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.8

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-Bp36xEIQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-Bp36xEIQ.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.7

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-DmCBX83O.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-DmCBX83O.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.6

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CvAgCuKp.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CvAgCuKp.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.5

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-DQ428u-U.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-DQ428u-U.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.4

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-CHa3rbfZ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-CHa3rbfZ.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.3

5 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/providers-BMeR_hLP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/providers-BMeR_hLP.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.2

4 findings
HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src/providers-WnAfnzLf.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: sklein12 → mdangelo (on 2025-12-09, known maintainer) provenance

This version was published by a different npm account (mdangelo) than the most recent previously approved version (sklein12) on 2025-12-09, but mdangelo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.120.1

5 findings
HIGH New obfuscated file: dist/src/data-DF-FvXLM.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src/providers-CS54SV62.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.120.0

5 findings
HIGH New obfuscated file: dist/src/data-DF-FvXLM.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/index.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/src/providers-CFAJHysk.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.119.14

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-eJ2lMe94.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-eJ2lMe94.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-1v4oeb7P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: sklein12 → GitHub Actions (on 2025-12-01, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-01, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.119.13

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-DifT6VGT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-DifT6VGT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-Bnh0UQ2S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/app/assets/vendor-mui-x-C2xF-yiO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.119.12

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-CXp6Lh_8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-CXp6Lh_8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-CVIuR1ht.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/app/assets/vendor-mui-x-C0Zq2q0Y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.119.11

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-C5kuLdph.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-C5kuLdph.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-CQ-TY82X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/app/assets/vendor-mui-x-C0Zq2q0Y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.119.10

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-Dn6NT1A2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-Dn6NT1A2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-XzfnsDIg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/app/assets/vendor-mui-x-C0Zq2q0Y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.119.9

5 findings
HIGH New obfuscated file: dist/src/app/assets/index-FpA-mwjL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/src/app/assets/index-FpA-mwjL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/src/app/assets/source-map-support-C99j8ebS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/app/assets/vendor-mui-x-B3p8MQbf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.