promptfoo
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:child-process-import | AI (semgrep): Python assertion execution feature; intrinsic to tool's eval functionality. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads user-specified local config file by extension; standard CLI pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Documented custom-eval assertion feature, expected user-controlled code execution. | ai | |
| source-diff | net-exec-file:dist/src/aws-DXcdBGfv.cjs | AI (source-diff): Bundled AWS Bedrock provider; network+require is core to the tool's provider integrations. | ai | |
| source-diff | net-exec-file:dist/src/providers-lmV8J0jR.cjs | AI (source-diff): Bundled providers module; net+exec inherent to eval provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/providers-lmV8J0jR.cjs | AI (source-diff): Minified bundler output, not true obfuscation; matches package build. | ai | |
| source-diff | obfuscated-file:dist/src/providers-DtkVivDo.cjs | AI (source-diff): tsdown-minified provider bundle; long lines are build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-DtkVivDo.cjs | AI (source-diff): Bundled provider module; network+exec expected for an LLM provider layer. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-FpA-mwjL.js | AI (source-diff): Bundled front-end app code; benign fetch/render, not a loader. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-B3p8MQbf.js | AI (source-diff): MUI-X vendor bundle; standard UI code. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-C99j8ebS.js | AI (source-diff): Minified source-map-support vendor bundle. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-FpA-mwjL.js | AI (source-diff): Vite-bundled SPA asset; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/src/providers-CgKOSgTR.cjs | AI (source-diff): Provider bundle legitimately makes network calls to LLM APIs; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CgKOSgTR.cjs | AI (source-diff): Minified bundler output (long lines), not true obfuscation; stable across releases. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CpUrPa8s.cjs | AI (source-diff): tsdown-minified build output, long lines are bundling not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-CpUrPa8s.cjs | AI (source-diff): Bundled providers module; net+exec expected for provider integrations. | ai | |
| source-diff | net-exec-file:dist/src/providers-DHbjzW2e.cjs | AI (source-diff): Bundled provider module; long lines are build minification. | ai | |
| source-diff | obfuscated-file:dist/src/providers-DHbjzW2e.cjs | AI (source-diff): Minified tsdown build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-BtzUfbxZ.cjs | AI (source-diff): Bundled provider module; net+exec expected for eval provider execution. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BtzUfbxZ.cjs | AI (source-diff): Minified tsdown bundle, not obfuscation; long lines are build artifacts. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-CEw_IGAd.js | AI (source-diff): Minified source-map-support vendor bundle. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-DcG0DpZ5.js | AI (source-diff): Bundled browser app; net+exec are normal SPA patterns, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-DcG0DpZ5.js | AI (source-diff): Vite-bundled React frontend asset; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/providers-D3WAfYou.cjs | AI (source-diff): Minified bundler output, not true obfuscation; stable for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/providers-D3WAfYou.cjs | AI (source-diff): Provider bundle legitimately makes network + exec calls; core function of the tool. | ai | |
| source-diff | net-exec-file:dist/src/providers-4g9A4cGL.cjs | AI (source-diff): Bundled provider module; minified build output, no true obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/src/providers-4g9A4cGL.cjs | AI (source-diff): tsdown-minified dist, long lines are build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BMeR_hLP.cjs | AI (source-diff): Minified bundler output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/providers-BMeR_hLP.cjs | AI (source-diff): Bundled provider module; network+exec are core to LLM provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-CVIuR1ht.js | AI (source-diff): Minified source-map-support vendor chunk. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-CXp6Lh_8.js | AI (source-diff): Bundled React/MUI app chunk; network+eval patterns are library code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-CXp6Lh_8.js | AI (source-diff): Vite-bundled frontend chunk; minified build output, regenerated each release. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-CQ-TY82X.js | AI (source-diff): Bundled source-map-support lib; minified vendor code. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-C5kuLdph.js | AI (source-diff): Vite-bundled SPA asset; minified build output, regenerated each release. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-C5kuLdph.js | AI (source-diff): Bundled React app runtime, not a loader; benign for this package. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-DvnJzB2w.js | AI (source-diff): Webapp bundle with normal fetch/dynamic-import; not a dropper. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-BmvzFAhR.js | AI (source-diff): Minified source-map-support vendor bundle. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-DvnJzB2w.js | AI (source-diff): Vite-bundled frontend asset; minified build output, regenerates each release. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-vA4qspBa.js | AI (source-diff): MUI-X vendor bundle; benign minified build output. | ai | |
| source-diff | obfuscated-file:dist/src/providers-DmCBX83O.cjs | AI (source-diff): Minified tsdown bundle output, not obfuscation; regenerated per release. | ai | |
| source-diff | net-exec-file:dist/src/providers-DmCBX83O.cjs | AI (source-diff): Provider bundle legitimately makes network+exec calls; build artifact. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-1v4oeb7P.js | AI (source-diff): Bundled source-map-support vendor chunk, minified build output. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-eJ2lMe94.js | AI (source-diff): Vite-bundled web UI output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-eJ2lMe94.js | AI (source-diff): Bundled SPA with fetch+dynamic import; benign vite build artifact. | ai | |
| source-diff | net-exec-file:dist/src/providers-CFAJHysk.cjs | AI (source-diff): Bundled provider module; network+exec expected for LLM provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BNk2AdyA.cjs | AI (source-diff): tsdown/rollup minified bundle, not obfuscation; stable build output. | ai | |
| source-diff | net-exec-file:dist/src/providers-BNk2AdyA.cjs | AI (source-diff): Bundled provider module; network+exec inherent to provider integrations. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-CDCJWS66.js | AI (source-diff): Bundled React app entry; import/fetch machinery, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-BPdSsBdq.js | AI (source-diff): Bundled source-map-support base64 VLQ codec; benign minified vendor code. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-B285qkCy.js | AI (source-diff): Bundled MUI-X DataGrid vendor chunk; benign build output. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-CDCJWS66.js | AI (source-diff): Vite-bundled web UI asset; minified not obfuscated, stable per release. | ai | |
| source-diff | net-exec-file:dist/src/providers-CS54SV62.cjs | AI (source-diff): Bundled provider modules calling LLM APIs; expected behavior. | ai | |
| source-diff | obfuscated-file:dist/src/data-DF-FvXLM.cjs | AI (source-diff): Bundled redteam prompt-injection dataset, long lines are JSON strings; stable for this package. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BNKVY53V.cjs | AI (source-diff): tsdown-minified provider bundle, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-BNKVY53V.cjs | AI (source-diff): Bundled provider module; network calls are the package's core function. | ai | |
| source-diff | net-exec-file:dist/src/providers-CFu-TZl-.cjs | AI (source-diff): Bundled provider module; network+exec expected for provider execution. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CFu-TZl-.cjs | AI (source-diff): Minified tsdown build output, not obfuscation; stable for this package's dist. | ai | |
| source-diff | net-exec-file:dist/src/providers-BWoVY_Wz.cjs | AI (source-diff): Bundled providers module; network+exec inherent to LLM provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BWoVY_Wz.cjs | AI (source-diff): Bundled/minified provider output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-WnAfnzLf.cjs | AI (source-diff): Bundled provider module of an LLM eval toolkit; network calls to LLM APIs are its core function. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CScd1wN6.cjs | AI (source-diff): tsdown-minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-CScd1wN6.cjs | AI (source-diff): Bundled provider module; network calls are the package's stated function. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BF4aullZ.cjs | AI (source-diff): Minified bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-BF4aullZ.cjs | AI (source-diff): Bundled providers module; network+exec is inherent to an LLM-provider toolkit. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-DifT6VGT.js | AI (source-diff): Bundled React app chunk; net+exec is normal SPA runtime, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-Bnh0UQ2S.js | AI (source-diff): Bundled source-map-support library; minified vite chunk. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-C2xF-yiO.js | AI (source-diff): Bundled MUI-X vendor chunk; icon/component code, benign build output. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-DifT6VGT.js | AI (source-diff): Vite-bundled web UI output with visible bundler banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-C0Zq2q0Y.js | AI (source-diff): Bundled MUI-X vendor chunk; benign build output. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-Dn6NT1A2.js | AI (source-diff): Bundled React app entry; net+exec are framework code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-Dn6NT1A2.js | AI (source-diff): Vite-bundled web-app entry; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-XzfnsDIg.js | AI (source-diff): Minified source-map-support vendor bundle. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Guarded hooks:install runs only in a .git checkout; no-op for consumers. | ai | |
| source-diff | obfuscated-file:dist/src/providers-Bz0U4NGd.cjs | AI (source-diff): Minified tsdown build output, not obfuscation; stable for this bundled package. | ai | |
| source-diff | obfuscated-file:dist/src/providers-Ce2-tX4F.cjs | AI (source-diff): Minified tsdown bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-Ce2-tX4F.cjs | AI (source-diff): Bundled provider registry; network+exec expected in an LLM eval tool. | ai | |
| source-diff | net-exec-file:dist/src/providers-DEJW_Mce.cjs | AI (source-diff): Bundled provider module; network+exec are core to the LLM provider layer. | ai | |
| source-diff | obfuscated-file:dist/src/providers-DEJW_Mce.cjs | AI (source-diff): tsdown-minified provider bundle; long lines are build output, no obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/src/providers-D1lUSO6m.cjs | AI (source-diff): Bundled providers module; network+exec expected for an LLM provider toolkit. | ai | |
| source-diff | obfuscated-file:dist/src/providers-D1lUSO6m.cjs | AI (source-diff): Minified tsdown bundle, long lines are build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-BuFfPRsl.cjs | AI (source-diff): Bundled provider module; network+exec expected for LLM eval tool. | ai | |
| source-diff | obfuscated-file:dist/src/providers-BuFfPRsl.cjs | AI (source-diff): Minified bundler output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/providers-CbcT30KA.cjs | AI (source-diff): Provider bundle; network+exec expected for LLM provider dispatch. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CbcT30KA.cjs | AI (source-diff): tsdown bundle output (long lines), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/providers-7NldzwUW.cjs | AI (source-diff): Minified bundler output, not obfuscation; recurs every build. | ai | |
| source-diff | net-exec-file:dist/src/providers-7NldzwUW.cjs | AI (source-diff): Bundled providers module; network+exec expected for LLM provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/providers-Bp36xEIQ.cjs | AI (source-diff): tsdown-bundled minified provider module, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/providers-Bp36xEIQ.cjs | AI (source-diff): Bundled provider module; network+exec are core to an LLM eval tool. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CvAgCuKp.cjs | AI (source-diff): Minified tsdown bundle, not obfuscation; long lines are build output. | ai | |
| source-diff | net-exec-file:dist/src/providers-CvAgCuKp.cjs | AI (source-diff): Bundled provider module; network+exec inherent to a multi-provider LLM tool. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-DTy7aidn.js | AI (source-diff): Bundled frontend SPA; net+exec is normal minified React app code. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-DTy7aidn.js | AI (source-diff): Vite-bundled minified webapp asset, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-BiIeb3Ol.js | AI (source-diff): Minified source-map-support lib in Vite bundle. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/vendor-mui-x-BZ0aDIR1.js | AI (source-diff): Bundled MUI-X vendor chunk; benign minified output. | ai | |
| source-diff | net-exec-file:dist/src/providers-CHa3rbfZ.cjs | AI (source-diff): Bundled providers module; net+exec expected for provider integrations. | ai | |
| source-diff | obfuscated-file:dist/src/providers-CHa3rbfZ.cjs | AI (source-diff): Minified/bundled build output, not true obfuscation. | ai | |
| npm-metadata | url-dep:rouge | AI (npm-metadata): Long-standing immutably SHA-pinned ROUGE metric lib; unchanged across versions. | ai | |
| source-diff | obfuscated-file:dist/src/providers-DQ428u-U.cjs | AI (source-diff): Minified tsdown bundle output, not obfuscation; long lines are build artifacts. | ai | |
| source-diff | net-exec-file:dist/src/providers-DQ428u-U.cjs | AI (source-diff): Bundled provider module; network+exec inherent to provider integrations. | ai | |
| source-diff | net-exec-file:dist/src/index.cjs | AI (source-diff): Bundled dist entrypoint of a build tool; net+exec is expected for an LLM eval CLI. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/index-iyBP4nBI.js | AI (source-diff): Vite-bundled web UI, minified not obfuscated; recurs every release. | ai | |
| source-diff | obfuscated-file:dist/src/app/assets/source-map-support-CSFI39ks.js | AI (source-diff): Minified source-map-support library, benign bundle chunk. | ai | |
| source-diff | net-exec-file:dist/src/app/assets/index-iyBP4nBI.js | AI (source-diff): Bundled React app; network+exec patterns are normal SPA build output. | ai | |
| dependencies | unvetted-dep:rouge | AI (dependencies): rouge is a well-known NLP scoring lib used for eval metrics, fits stated purpose. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Mature legitimate package; README/keyword heuristics are false positives here. | ai | |
| source-diff | net-exec-file:dist/src/aws-Dao2vq-8.cjs | AI (source-diff): Rolldown-bundled Bedrock provider; network+require are legit AWS/AI SDK usage, not a loader. | ai | |
| source-diff | net-exec-file:dist/src/aws-DZ0G882T.cjs | AI (source-diff): Bundled AWS Bedrock provider; network+exec is inherent to this LLM eval tool's purpose. | ai | |
| source-diff | net-exec-file:dist/src/aws-D54hswwK.cjs | AI (source-diff): Bundled AWS Bedrock provider; network+exec pattern is inherent to LLM provider SDK wrappers. | ai | |
| source-diff | net-exec-file:dist/src/aws-B6z7Bp-y.cjs | AI (source-diff): Bundled AWS Bedrock provider; network+exec is inherent to an LLM eval toolkit calling cloud APIs. | ai | |
| source-diff | net-exec-file:dist/src/evalResult-BgL2HNJC.cjs | AI (source-diff): Rolldown-bundled CJS chunk; network+require pattern is normal for bundled output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundler migration (rolldown) causes chunk filename churn; stable pattern for this package. | ai | |
| source-diff | net-exec-file:dist/src/aws-CcirYqo_.cjs | AI (source-diff): Rolldown-bundled CJS chunk for AWS Bedrock provider; network+require pattern is normal for this package. | ai | |
| phantom-deps | phantom-dep:gcp-metadata | AI (phantom-deps): Referenced in config/override context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-base | AI (phantom-deps): OTel SDK loaded via plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opencode-ai/sdk | AI (phantom-deps): Optional provider integration; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): Type-only dep; used as framework-scoped type declaration, not a direct import. | ai |
Versions (showing 51 of 208)
| Version | Deps | Published |
|---|---|---|
| 0.121.19 | 79 / 55 | |
| 0.121.18 | 79 / 57 | |
| 0.121.17 | 78 / 57 | |
| 0.121.16 | 78 / 57 | |
| 0.121.15 | 78 / 56 | |
| 0.121.14 | 78 / 56 | |
| 0.121.13 | 78 / 56 | |
| 0.121.12 | 84 / 57 | |
| 0.121.11 | 83 / 57 | |
| 0.121.10 | 83 / 57 | |
| 0.121.9 | 85 / 58 | |
| 0.121.8 | 85 / 58 | |
| 0.121.7 | 85 / 58 | |
| 0.121.5 | 85 / 57 | |
| 0.121.4 | 85 / 57 | |
| 0.121.3 | 85 / 58 | |
| 0.121.2 | 85 / 58 | |
| 0.121.1 | 84 / 59 | |
| 0.120.27 | 84 / 59 | |
| 0.120.26 | 84 / 59 | |
| 0.120.25 | 84 / 59 | |
| 0.120.24 | 84 / 59 | |
| 0.120.23 | 84 / 59 | |
| 0.120.22 | 84 / 59 | |
| 0.120.21 | 84 / 59 | |
| 0.120.20 | 84 / 59 | |
| 0.120.19 | 84 / 59 | |
| 0.120.18 | 84 / 59 | |
| 0.120.17 | 85 / 58 | |
| 0.120.16 | 85 / 58 | |
| 0.120.15 | 85 / 57 | |
| 0.120.14 | 83 / 57 | |
| 0.120.13 | 83 / 57 | |
| 0.120.12 | 82 / 56 | |
| 0.120.11 | 82 / 67 | |
| 0.120.10 | 82 / 67 | |
| 0.120.8 | 82 / 67 | |
| 0.120.7 | 82 / 67 | |
| 0.120.6 | 82 / 67 | |
| 0.120.5 | 76 / 68 | |
| 0.120.4 | 75 / 68 | |
| 0.120.3 | 74 / 68 | |
| 0.120.2 | 74 / 68 | |
| 0.120.1 | 73 / 68 | |
| 0.120.0 | 73 / 68 | |
| 0.119.14 | 73 / 75 | |
| 0.119.13 | 73 / 74 | |
| 0.119.12 | 73 / 73 | |
| 0.119.11 | 73 / 73 | |
| 0.119.10 | 73 / 73 | |
| 0.119.9 | 73 / 74 |
v0.121.19
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.121.18
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.121.3
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.121.2
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.121.1
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.27
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.26
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-03-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.25
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.24
6 findingsScript: [ -d .git ] && npm run hooks:install || true
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.23
6 findingsScript: [ -d .git ] && npm run hooks:install || true
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.22
6 findingsScript: [ -d .git ] && npm run hooks:install || true
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.21
6 findingsScript: [ -d .git ] && npm run hooks:install || true
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-02-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.20
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.19
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.18
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.17
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.16
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.15
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.14
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.13
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.12
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.11
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.10
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2026-01-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.8
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.7
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.6
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.5
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.4
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.3
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.2
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mdangelo) than the most recent previously approved version (sklein12) on 2025-12-09, but mdangelo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.120.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.120.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.119.14
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (sklein12) on 2025-12-01, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.119.13
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.12
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.11
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.10
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.9
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.