solc
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads versioned soljson compiler binary; core design of solc-js. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs backs the solcjs CLI bin; legitimate use. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() is core EVM bytecode execution in bundled ethereumjs-vm; stable for this package. | ai | |
| source-diff | encoded-string-file:soljson.js | AI (source-diff): soljson.js is the compiled emscripten WASM base64 blob; expected build artifact for this package. | ai | |
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer; gitHead absence is benign for this package's release flow. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): Documented EF team handoff (chriseth→ekpyron/cameel/r0qs et al.) on the official ethereum/solc-js package. | ai | |
| source-diff | net-exec-file:soljson.js | AI (source-diff): Base64/WASM decode loop, not network+exec dropper; core compiler artifact. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 9.6MB soljson.js compiler blob is expected for solc. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected file layout for the compiler bindings. | ai | |
| source-diff | obfuscated-file:soljson.js | AI (source-diff): soljson.js is the Emscripten-compiled Solidity WASM compiler; long lines are generated build output, not obfuscation. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): solc-js legitimately uses child_process to invoke SMT solver binaries (z3, cvc4) as part of its SMT checker integration. This is expected and documented behavior. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is used by the solcjs CLI binary; phantom-dep detection is a false positive for this package's CLI usage pattern. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): fs-extra is used in the solcjs CLI tooling; phantom-dep detection is a false positive for this package's CLI usage pattern. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.8.36 | 7 / 17 | |
| 0.8.35 | 7 / 17 | |
| 0.8.34 | 7 / 17 | |
| 0.8.33 | 7 / 17 | |
| 0.8.32 | 7 / 17 | |
| 0.8.31 | 7 / 17 | |
| 0.7.3 | 9 / 5 | |
| 0.4.1 | 3 / 3 | |
| 0.3.5 | 2 / 2 | |
| 0.1.4 | 0 / 0 |
v0.8.36
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nikola-matic.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikola-matic) than the most recent previously approved version (r0qs) on 2026-07-09, but nikola-matic is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.35
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nikola-matic.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (nikola-matic) than the most recent previously approved version (r0qs) on 2026-04-29, but nikola-matic is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.8.33
6 findingsAll previous maintainers (d11e9, chriseth) were replaced by new maintainers (ekpyron, cameel, r0qs, matheus.pit, clonker, nikola-matic). This is a strong signal of a potential package hijack and requires careful review.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: matheus.pit.
This version was published by a different npm account than previous versions on 2025-12-18. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.32
6 findingsAll previous maintainers (d11e9, chriseth) were replaced by new maintainers (ekpyron, cameel, r0qs, matheus.pit, clonker, nikola-matic). This is a strong signal of a potential package hijack and requires careful review.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: nikola-matic.
This version was published by a different npm account than previous versions on 2025-12-18. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.31
6 findingsAll previous maintainers (d11e9, chriseth) were replaced by new maintainers (ekpyron, cameel, nikola.matic, r0qs, matheus.pit, clonker). This is a strong signal of a potential package hijack and requires careful review.
This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: r0qs.
This version was published by a different npm account than previous versions on 2025-12-03. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
2 findingsMaintainer email '[email protected]' uses domain 'turkd.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.5
2 findingsMaintainer email '[email protected]' uses domain 'turkd.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
2 findingsMaintainer email '[email protected]' uses domain 'turkd.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.