vercel
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Bundled build output (esbuild), not obfuscated code; standard for this CLI's dist chunks. | ai | |
| phantom-deps | phantom-dep:jose | AI (phantom-deps): Framework-scoped dependency loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/fun | AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/detect-agent | AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/blob | AI (phantom-deps): Framework-scoped package loaded by convention; stable pattern for this package. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-HZAINEXG.js | AI (source-diff): Bundled CLI chunk; network+exec is inherent to the Vercel CLI, not malicious. Path is version-specific but pattern stable. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-2MXGTALG.js | AI (source-diff): Bundled esbuild CLI chunk; network+exec is inherent to the deploy tool, not malware. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-RGOP4OYL.js | AI (source-diff): Bundled CLI chunk; network+exec is core deploy-tool function, no hostile target. Path is version-specific but pattern stable. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-CNBOV577.js | AI (source-diff): Bundled exec chunk in official CLI; expected process/network use. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-DDEPCAGE.js | AI (source-diff): Bundled CLI command chunk; net+exec is inherent to a deploy CLI, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-CNBOV577.js | AI (source-diff): esbuild bundle output (vendored edge-runtime), minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-YGSTSVXS.js | AI (source-diff): Bundled CLI chunk; network+exec inherent to a deploy CLI, no hostile target. Filename varies per build so scope is broad but stable. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-THMFJODG.js | AI (source-diff): Bundled CLI command dispatcher; createRequire+internal imports are normal esbuild output for this canonical package. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-TLHKETA6.js | AI (source-diff): Bundled esbuild CLI chunk; network+exec is inherent to Vercel CLI, no hostile target. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Config-file parser referenced indirectly; stable FP for this CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-F6YGVA2L.js | AI (source-diff): esbuild-bundled Vercel CLI chunk; network+exec is normal CLI behavior, chunk hashes change per release. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-DNEOCFVV.js | AI (source-diff): Bundled CLI chunk; net+exec is core to a deploy CLI, no hostile target. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-BHMMV3HE.js | AI (source-diff): Bundled CLI chunk; network+exec inherent to deploy CLI, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-G4AUF3KG.js | AI (source-diff): Minified esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-G4AUF3KG.js | AI (source-diff): Bundled esbuild chunk; net+exec expected for Vercel CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-XHC5YRFY.js | AI (source-diff): Bundled esbuild chunk of the official Vercel CLI; net+exec inherent to a deploy tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-IR674PKY.js | AI (source-diff): Bundled CLI chunk; network+exec is inherent to Vercel's deploy CLI, SLSA-attested from official repo. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-45H2JIQ2.js | AI (source-diff): Bundled CLI chunk; network+require are inherent to the CLI's function, not exfil. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-URENS2ZN.js | AI (source-diff): Bundled esbuild chunk for the CLI; network+exec is inherent to the tool, no exfil target. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-RB7WQKNC.js | AI (source-diff): Bundled CLI chunk; network+exec is the CLI's legit function, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-UKMIYIF6.js | AI (source-diff): esbuild-minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-UKMIYIF6.js | AI (source-diff): Bundled which/execa exec logic; normal CLI capability. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-S6WD5L3L.js | AI (source-diff): Bundled CLI dist chunk; net+exec is legitimate CLI functionality, chunk names vary per build. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-LUORN5H7.js | AI (source-diff): esbuild-bundled CLI chunk; network+exec is inherent to a deploy CLI, no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-I4NRKN2Z.js | AI (source-diff): Bundled CLI dist chunk; network+require are core to the Vercel CLI, no hostile target. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @vercel/container is a first-party Vercel-scoped dependency. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-KTX4RQFM.js | AI (source-diff): Bundled CLI chunk; network+exec is core CLI functionality, not a dropper. Stable for this package. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-INFYZRHS.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI tool. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-CGBHRYWG.js | AI (source-diff): esbuild bundle output with long lines; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-CGBHRYWG.js | AI (source-diff): Bundled CLI chunk inlining which/execa; expected for a CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-VUVQO3LF.js | AI (source-diff): Bundled CLI chunk with network+exec is expected for the Vercel CLI. | ai | |
| phantom-deps | phantom-dep:@vercel/container | AI (phantom-deps): Framework-scoped package loaded by convention, like all other @vercel/* phantom deps. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-MABHXDYV.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; stable false positive. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-SFPJ3VR7.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI; chunk names rotate each build. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-YIAUEFUY.js | AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-LQR3CHMH.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable FP for vercel CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-XLLAD5DR.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; not malicious. | ai | |
| dependencies | unvetted-dep:sandbox | AI (dependencies): sandbox is a known utility used by @vercel/fun for local serverless function execution; stable legitimate use for this CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-5UCWXYNH.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel deployment CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-EF7I74B3.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-QNCTSLLG.js | AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for Vercel CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-IDTFK3CR.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-4AYB4D6T.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for vercel CLI; not malicious. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-T77OYIET.js | AI (source-diff): Bundled CLI chunk with standard Node imports; expected for a full-featured CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-CNZVD6AY.js | AI (source-diff): Bundled CLI chunk; network+exec is normal for a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-HI4HF4GY.js | AI (source-diff): Bundles which/execa for subprocess management; expected CLI behavior. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-HI4HF4GY.js | AI (source-diff): Esbuild-bundled output with long lines; not obfuscation, just minified build artifact. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-GSR2GQLJ.js | AI (source-diff): Esbuild bundle of CLI internals; network+exec is expected for a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-H3M6DIPE.js | AI (source-diff): Bundled CLI chunk; network + exec is expected for a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-GIJMTTDG.js | AI (source-diff): Bundled CLI chunk; network + exec is inherent to a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-KFVMKDQD.js | AI (source-diff): Bundled CLI chunk; network+exec is expected for a deployment CLI tool. | ai | |
| source-diff | obfuscated-file:dist/chunks/exec-JSOL4CYJ.js | AI (source-diff): Bundled output with long lines; not obfuscated, just minified build artifact. | ai | |
| source-diff | net-exec-file:dist/chunks/exec-JSOL4CYJ.js | AI (source-diff): Bundled CLI chunk wrapping which/execa; expected for CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-QAHIBMRJ.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable FP for this package. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-CWRL2B64.js | AI (source-diff): Bundled CLI chunk with network+exec is expected for the Vercel CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-V2EPUZ7C.js | AI (source-diff): Bundled CLI chunk with network+exec is normal for the Vercel CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-W5RSXTBT.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns for a deployment CLI tool. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-PKUYGVBJ.js | AI (source-diff): Bundled CLI chunk with expected network+exec patterns; stable for vercel CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-RNIZUKES.js | AI (source-diff): Bundled CLI chunk with network+exec is expected for Vercel CLI; not malicious. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Chunk filenames rotate on each build; large bundles are normal for this CLI. | ai | |
| source-diff | net-exec-file:dist/chunks/chunk-L3JT6XDK.js | AI (source-diff): Bundled CLI chunk with standard network+exec patterns; expected for a deployment CLI tool. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): matheuss is a known Vercel team member; stable for this package. | ai | |
| phantom-deps | phantom-dep:@vercel/remix-builder | AI (phantom-deps): Framework adapter loaded by convention. | ai | |
| phantom-deps | phantom-dep:@vercel/backends | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/redwood | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/fastify | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/express | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/python | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/nestjs | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/elysia | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/rust | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/ruby | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/node | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/next | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/hono | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/koa | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/h3 | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/go | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): Referenced in config files by convention; stable false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:parcel | AI (typosquat): vercel is the canonical Vercel CLI brand, not a typosquat of parcel. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is a known runtime/binary implicit dependency for this CLI build tool. | ai | |
| phantom-deps | phantom-dep:@vercel/static-build | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vercel/hydrogen | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai |
Versions (showing 51 of 154)
| Version | Deps | Published |
|---|---|---|
| 56.4.0 | 35 / 128 | |
| 56.3.2 | 35 / 128 | |
| 56.3.1 | 35 / 128 | |
| 56.3.0 | 35 / 128 | |
| 56.2.1 | 35 / 128 | |
| 56.2.0 | 36 / 128 | |
| 56.1.0 | 36 / 128 | |
| 56.0.0 | 36 / 128 | |
| 55.0.0 | 35 / 128 | |
| 54.21.1 | 35 / 128 | |
| 54.21.0 | 35 / 128 | |
| 54.20.1 | 35 / 126 | |
| 54.20.0 | 35 / 126 | |
| 54.19.0 | 35 / 126 | |
| 54.18.7 | 35 / 126 | |
| 54.18.6 | 35 / 126 | |
| 54.18.5 | 35 / 126 | |
| 54.18.4 | 35 / 126 | |
| 54.18.3 | 35 / 126 | |
| 54.18.2 | 35 / 126 | |
| 54.18.1 | 35 / 126 | |
| 54.18.0 | 35 / 126 | |
| 54.17.3 | 35 / 128 | |
| 54.17.2 | 35 / 128 | |
| 54.17.1 | 35 / 128 | |
| 54.17.0 | 35 / 128 | |
| 54.16.0 | 35 / 128 | |
| 54.15.1 | 34 / 128 | |
| 54.15.0 | 34 / 128 | |
| 54.14.5 | 34 / 128 | |
| 54.14.2 | 34 / 128 | |
| 54.14.1 | 34 / 128 | |
| 54.14.0 | 34 / 128 | |
| 54.13.0 | 34 / 128 | |
| 54.12.2 | 34 / 128 | |
| 54.12.1 | 34 / 128 | |
| 54.12.0 | 34 / 128 | |
| 54.11.1 | 34 / 128 | |
| 54.11.0 | 34 / 128 | |
| 54.10.3 | 34 / 128 | |
| 54.10.2 | 34 / 128 | |
| 54.10.1 | 34 / 128 | |
| 54.10.0 | 34 / 128 | |
| 54.9.1 | 34 / 128 | |
| 54.9.0 | 34 / 128 | |
| 54.8.0 | 34 / 128 | |
| 54.7.1 | 33 / 128 | |
| 54.7.0 | 33 / 128 | |
| 54.6.1 | 33 / 128 | |
| 54.6.0 | 33 / 128 | |
| 54.5.1 | 33 / 128 |
v56.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.3.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.3.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.3.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.2.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.2.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.1.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v56.0.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v55.0.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.21.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.21.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.20.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.20.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.19.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.7
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.6
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.5
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.4
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.3
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v54.18.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.