← Home

vercel

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussrauchgmatt.strakavercel-release-botzeit-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff bulk-net-exec-files:dist AI (source-diff): Bundled build output (esbuild), not obfuscated code; standard for this CLI's dist chunks. ai
phantom-deps phantom-dep:jose AI (phantom-deps): Framework-scoped dependency loaded by convention; stable pattern for this package. ai
phantom-deps phantom-dep:@vercel/fun AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Referenced in config; stable pattern for this package. ai
phantom-deps phantom-dep:@vercel/detect-agent AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. ai
phantom-deps phantom-dep:@vercel/blob AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. ai
source-diff net-exec-file:dist/chunks/chunk-HZAINEXG.js AI (source-diff): Bundled CLI chunk; network+exec is inherent to the Vercel CLI, not malicious. Path is version-specific but pattern stable. ai
source-diff net-exec-file:dist/chunks/chunk-2MXGTALG.js AI (source-diff): Bundled esbuild CLI chunk; network+exec is inherent to the deploy tool, not malware. ai
source-diff net-exec-file:dist/chunks/chunk-RGOP4OYL.js AI (source-diff): Bundled CLI chunk; network+exec is core deploy-tool function, no hostile target. Path is version-specific but pattern stable. ai
source-diff net-exec-file:dist/chunks/exec-CNBOV577.js AI (source-diff): Bundled exec chunk in official CLI; expected process/network use. ai
source-diff net-exec-file:dist/chunks/chunk-DDEPCAGE.js AI (source-diff): Bundled CLI command chunk; net+exec is inherent to a deploy CLI, no hostile target. ai
source-diff obfuscated-file:dist/chunks/exec-CNBOV577.js AI (source-diff): esbuild bundle output (vendored edge-runtime), minified not obfuscated. ai
source-diff net-exec-file:dist/chunks/chunk-YGSTSVXS.js AI (source-diff): Bundled CLI chunk; network+exec inherent to a deploy CLI, no hostile target. Filename varies per build so scope is broad but stable. ai
source-diff net-exec-file:dist/chunks/chunk-THMFJODG.js AI (source-diff): Bundled CLI command dispatcher; createRequire+internal imports are normal esbuild output for this canonical package. ai
source-diff net-exec-file:dist/chunks/chunk-TLHKETA6.js AI (source-diff): Bundled esbuild CLI chunk; network+exec is inherent to Vercel CLI, no hostile target. ai
phantom-deps phantom-dep:jsonc-parser AI (phantom-deps): Config-file parser referenced indirectly; stable FP for this CLI. ai
source-diff net-exec-file:dist/chunks/chunk-F6YGVA2L.js AI (source-diff): esbuild-bundled Vercel CLI chunk; network+exec is normal CLI behavior, chunk hashes change per release. ai
source-diff net-exec-file:dist/chunks/chunk-DNEOCFVV.js AI (source-diff): Bundled CLI chunk; net+exec is core to a deploy CLI, no hostile target. ai
source-diff net-exec-file:dist/chunks/chunk-BHMMV3HE.js AI (source-diff): Bundled CLI chunk; network+exec inherent to deploy CLI, no hostile target. ai
source-diff obfuscated-file:dist/chunks/exec-G4AUF3KG.js AI (source-diff): Minified esbuild bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/chunks/exec-G4AUF3KG.js AI (source-diff): Bundled esbuild chunk; net+exec expected for Vercel CLI. ai
source-diff net-exec-file:dist/chunks/chunk-XHC5YRFY.js AI (source-diff): Bundled esbuild chunk of the official Vercel CLI; net+exec inherent to a deploy tool. ai
source-diff net-exec-file:dist/chunks/chunk-IR674PKY.js AI (source-diff): Bundled CLI chunk; network+exec is inherent to Vercel's deploy CLI, SLSA-attested from official repo. ai
source-diff net-exec-file:dist/chunks/chunk-45H2JIQ2.js AI (source-diff): Bundled CLI chunk; network+require are inherent to the CLI's function, not exfil. ai
source-diff net-exec-file:dist/chunks/chunk-URENS2ZN.js AI (source-diff): Bundled esbuild chunk for the CLI; network+exec is inherent to the tool, no exfil target. ai
source-diff net-exec-file:dist/chunks/chunk-RB7WQKNC.js AI (source-diff): Bundled CLI chunk; network+exec is the CLI's legit function, no hostile destination. ai
source-diff obfuscated-file:dist/chunks/exec-UKMIYIF6.js AI (source-diff): esbuild-minified bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/chunks/exec-UKMIYIF6.js AI (source-diff): Bundled which/execa exec logic; normal CLI capability. ai
source-diff net-exec-file:dist/chunks/chunk-S6WD5L3L.js AI (source-diff): Bundled CLI dist chunk; net+exec is legitimate CLI functionality, chunk names vary per build. ai
source-diff net-exec-file:dist/chunks/chunk-LUORN5H7.js AI (source-diff): esbuild-bundled CLI chunk; network+exec is inherent to a deploy CLI, no hostile destination. ai
source-diff net-exec-file:dist/chunks/chunk-I4NRKN2Z.js AI (source-diff): Bundled CLI dist chunk; network+require are core to the Vercel CLI, no hostile target. ai
publish-pattern new-deps-added AI (publish-pattern): @vercel/container is a first-party Vercel-scoped dependency. ai
source-diff net-exec-file:dist/chunks/chunk-KTX4RQFM.js AI (source-diff): Bundled CLI chunk; network+exec is core CLI functionality, not a dropper. Stable for this package. ai
source-diff net-exec-file:dist/chunks/chunk-INFYZRHS.js AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI tool. ai
source-diff obfuscated-file:dist/chunks/exec-CGBHRYWG.js AI (source-diff): esbuild bundle output with long lines; not obfuscation. ai
source-diff net-exec-file:dist/chunks/exec-CGBHRYWG.js AI (source-diff): Bundled CLI chunk inlining which/execa; expected for a CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-VUVQO3LF.js AI (source-diff): Bundled CLI chunk with network+exec is expected for the Vercel CLI. ai
phantom-deps phantom-dep:@vercel/container AI (phantom-deps): Framework-scoped package loaded by convention, like all other @vercel/* phantom deps. ai
source-diff net-exec-file:dist/chunks/chunk-MABHXDYV.js AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; stable false positive. ai
source-diff net-exec-file:dist/chunks/chunk-SFPJ3VR7.js AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI; chunk names rotate each build. ai
source-diff net-exec-file:dist/chunks/chunk-YIAUEFUY.js AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-LQR3CHMH.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable FP for vercel CLI. ai
source-diff net-exec-file:dist/chunks/chunk-XLLAD5DR.js AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; not malicious. ai
dependencies unvetted-dep:sandbox AI (dependencies): sandbox is a known utility used by @vercel/fun for local serverless function execution; stable legitimate use for this CLI. ai
source-diff net-exec-file:dist/chunks/chunk-5UCWXYNH.js AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel deployment CLI. ai
source-diff net-exec-file:dist/chunks/chunk-EF7I74B3.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment tool. ai
source-diff net-exec-file:dist/chunks/chunk-QNCTSLLG.js AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for Vercel CLI. ai
source-diff net-exec-file:dist/chunks/chunk-IDTFK3CR.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment tool. ai
source-diff net-exec-file:dist/chunks/chunk-4AYB4D6T.js AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; not malicious. ai
source-diff net-exec-file:dist/chunks/chunk-T77OYIET.js AI (source-diff): Bundled CLI chunk with standard Node imports; expected for a full-featured CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-CNZVD6AY.js AI (source-diff): Bundled CLI chunk; network+exec is normal for a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/exec-HI4HF4GY.js AI (source-diff): Bundles which/execa for subprocess management; expected CLI behavior. ai
source-diff obfuscated-file:dist/chunks/exec-HI4HF4GY.js AI (source-diff): Esbuild-bundled output with long lines; not obfuscation, just minified build artifact. ai
source-diff net-exec-file:dist/chunks/chunk-GSR2GQLJ.js AI (source-diff): Esbuild bundle of CLI internals; network+exec is expected for a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-H3M6DIPE.js AI (source-diff): Bundled CLI chunk; network + exec is expected for a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-GIJMTTDG.js AI (source-diff): Bundled CLI chunk; network + exec is inherent to a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-KFVMKDQD.js AI (source-diff): Bundled CLI chunk; network+exec is expected for a deployment CLI tool. ai
source-diff obfuscated-file:dist/chunks/exec-JSOL4CYJ.js AI (source-diff): Bundled output with long lines; not obfuscated, just minified build artifact. ai
source-diff net-exec-file:dist/chunks/exec-JSOL4CYJ.js AI (source-diff): Bundled CLI chunk wrapping which/execa; expected for CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-QAHIBMRJ.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable FP for this package. ai
source-diff net-exec-file:dist/chunks/chunk-CWRL2B64.js AI (source-diff): Bundled CLI chunk with network+exec is expected for the Vercel CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-V2EPUZ7C.js AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-W5RSXTBT.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment CLI tool. ai
source-diff net-exec-file:dist/chunks/chunk-PKUYGVBJ.js AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable for vercel CLI. ai
source-diff net-exec-file:dist/chunks/chunk-RNIZUKES.js AI (source-diff): Bundled CLI chunk with network+exec is expected for Vercel CLI; not malicious. ai
source-diff large-new-source-files AI (source-diff): Chunk filenames rotate on each build; large bundles are normal for this CLI. ai
source-diff net-exec-file:dist/chunks/chunk-L3JT6XDK.js AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for a deployment CLI tool. ai
maintainer-change maintainer-added AI (maintainer-change): matheuss is a known Vercel team member; stable for this package. ai
phantom-deps phantom-dep:@vercel/remix-builder AI (phantom-deps): Framework adapter loaded by convention. ai
phantom-deps phantom-dep:@vercel/backends AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/redwood AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/fastify AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/express AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/python AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/nestjs AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/elysia AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/rust AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/ruby AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/node AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/next AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/hono AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/koa AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/h3 AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/go AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:smol-toml AI (phantom-deps): Referenced in config files by convention; stable false positive for this package. ai
typosquat typosquat.levenshtein:parcel AI (typosquat): vercel is the canonical Vercel CLI brand, not a typosquat of parcel. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): esbuild is a known runtime/binary implicit dependency for this CLI build tool. ai
phantom-deps phantom-dep:@vercel/static-build AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@vercel/hydrogen AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai

Versions (showing 51 of 154)

View all versions
Version Deps Published
56.4.0 35 / 128
56.3.2 35 / 128
56.3.1 35 / 128
56.3.0 35 / 128
56.2.1 35 / 128
56.2.0 36 / 128
56.1.0 36 / 128
56.0.0 36 / 128
55.0.0 35 / 128
54.21.1 35 / 128
54.21.0 35 / 128
54.20.1 35 / 126
54.20.0 35 / 126
54.19.0 35 / 126
54.18.7 35 / 126
54.18.6 35 / 126
54.18.5 35 / 126
54.18.4 35 / 126
54.18.3 35 / 126
54.18.2 35 / 126
54.18.1 35 / 126
54.18.0 35 / 126
54.17.3 35 / 128
54.17.2 35 / 128
54.17.1 35 / 128
54.17.0 35 / 128
54.16.0 35 / 128
54.15.1 34 / 128
54.15.0 34 / 128
54.14.5 34 / 128
54.14.2 34 / 128
54.14.1 34 / 128
54.14.0 34 / 128
54.13.0 34 / 128
54.12.2 34 / 128
54.12.1 34 / 128
54.12.0 34 / 128
54.11.1 34 / 128
54.11.0 34 / 128
54.10.3 34 / 128
54.10.2 34 / 128
54.10.1 34 / 128
54.10.0 34 / 128
54.9.1 34 / 128
54.9.0 34 / 128
54.8.0 34 / 128
54.7.1 33 / 128
54.7.0 33 / 128
54.6.1 33 / 128
54.6.0 33 / 128
54.5.1 33 / 128

v56.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.3.2

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-HZAINEXG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.3.1

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-RGOP4OYL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.3.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-2MXGTALG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.2.1

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-DDEPCAGE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-CNBOV577.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-CNBOV577.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.2.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-YGSTSVXS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.1.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-TLHKETA6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v56.0.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-THMFJODG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v55.0.0

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-XHC5YRFY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-G4AUF3KG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-G4AUF3KG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.21.1

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-I4NRKN2Z.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.21.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-IR674PKY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.20.1

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-RB7WQKNC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.20.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-RB7WQKNC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.19.0

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-RB7WQKNC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.7

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-RB7WQKNC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.6

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-F6YGVA2L.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.5

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-F6YGVA2L.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.4

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-DNEOCFVV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-UKMIYIF6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.3

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-45H2JIQ2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.2

2 findings
HIGH New file with network + code execution: dist/chunks/chunk-URENS2ZN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.1

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-S6WD5L3L.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-CGBHRYWG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-CGBHRYWG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v54.18.0

4 findings
HIGH New file with network + code execution: dist/chunks/chunk-VUVQO3LF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/chunks/exec-CGBHRYWG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/chunks/exec-CGBHRYWG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.