vod-js-sdk-v6
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/base.js | AI (source-diff): Bundled dependency code, not obfuscation. | ai | |
| phantom-deps | phantom-dep:cos-js-sdk-v5 | AI (phantom-deps): Used via bundled dist, heuristic false positive. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): 981 days live on npm without unpublish; consistent with legitimate transfer. | ai | |
| source-diff | net-exec-file:src/cos-js-sdk-v5.js | AI (source-diff): Official cos-js-sdk-v5 webpack bundle, expected content. | ai | |
| source-diff | net-exec-file:src/base.js | AI (source-diff): Bundled dependency code. | ai | |
| source-diff | obfuscated-file:lib/src/base.js | AI (source-diff): Bundled cos-js-sdk-v5 webpack UMD output, not injected obfuscation. | ai | |
| source-diff | net-exec-file:lib/src/base.js | AI (source-diff): Same vendored bundle; no concrete malicious network/exec behavior. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): fsevents native .node binary inside committed demo node_modules, standard macOS optional dep, not a backdoor. | ai | |
| vendored-integrity | tampered-vendored-dep:docs/import-demo/node_modules/atob | AI (vendored-integrity): Committed demo node_modules; sole diff is npm install-time package.json metadata (_resolved/_where), no code payload. | ai | |
| source-diff | obfuscated-file:docs/import-demo/node_modules/vue/dist/vue.common.prod.js | AI (source-diff): Stock minified Vue bundle in committed demo node_modules; not obfuscation. | ai | |
| source-diff | net-exec-file:docs/import-demo/node_modules/vue/dist/vue.common.prod.js | AI (source-diff): Stock minified Vue library in committed demo tree; no dropper behavior. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): uuid and eventemitter3 are well-known established deps. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Long-stable legitimate publisher change from 2020, unchanged since. | ai | |
| source-diff | encoded-string-file:test/uploader.test.ts | AI (source-diff): Base64 strings are mocked test fixtures for upload signatures, not hidden payloads. | ai | |
| source-diff | net-exec-file:docs/import-demo/bundle.js | AI (source-diff): Bundled webpack demo posting to Tencent's own demo upload endpoint, not a dropper. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Same bundled demo file; build artifact, not obfuscation. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Fires inside bundled third-party libs (sha1/Vue) within webpack demo bundle. | ai |
Versions (showing 47 of 47)
| Version | Deps | Published |
|---|---|---|
| 1.8.0 | 7 / 22 | |
| 1.7.4 | 6 / 22 | |
| 1.7.3 | 5 / 22 | |
| 1.7.2 | 5 / 22 | |
| 1.7.0 | 6 / 22 | |
| 1.6.2 | 6 / 22 | |
| 1.6.1 | 5 / 23 | |
| 1.6.0 | 5 / 23 | |
| 1.5.0 | 5 / 23 | |
| 1.4.16 | 5 / 23 | |
| 1.4.15 | 5 / 23 | |
| 1.4.14 | 5 / 23 | |
| 1.4.13 | 5 / 23 | |
| 1.4.12 | 5 / 23 | |
| 1.4.11 | 4 / 23 | |
| 1.4.10 | 4 / 23 | |
| 1.4.9 | 4 / 23 | |
| 1.4.8 | 4 / 23 | |
| 1.4.7 | 4 / 22 | |
| 1.4.6 | 4 / 22 | |
| 1.4.5 | 4 / 22 | |
| 1.4.4 | 4 / 22 | |
| 1.4.3 | 4 / 22 | |
| 1.4.2 | 4 / 22 | |
| 1.4.1 | 4 / 22 | |
| 1.4.0 | 4 / 22 | |
| 1.3.3 | 3 / 21 | |
| 1.3.2 | 3 / 21 | |
| 1.3.1 | 3 / 21 | |
| 1.2.11 | 3 / 13 | |
| 1.2.10 | 3 / 13 | |
| 1.2.9 | 3 / 13 | |
| 1.2.8 | 3 / 13 | |
| 1.2.7 | 3 / 13 | |
| 1.2.6 | 3 / 13 | |
| 1.2.4 | 3 / 13 | |
| 1.2.3 | 3 / 13 | |
| 1.2.2 | 3 / 13 | |
| 1.2.1 | 3 / 13 | |
| 1.2.0 | 3 / 13 | |
| 1.1.6 | 3 / 13 | |
| 1.1.5 | 3 / 12 | |
| 1.1.4 | 3 / 11 | |
| 1.1.3 | 3 / 11 | |
| 1.1.2 | 3 / 11 | |
| 1.1.0 | 3 / 11 | |
| 1.0.0 | 3 / 11 |
v1.7.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (superjolly) than the most recent previously approved version (alsotang) on 2023-11-13. It has since remained available on npm for 981 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-07-26. It has since remained available on npm for 1091 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.1
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-02-06. It has since remained available on npm for 1261 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-02-03. It has since remained available on npm for 1264 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-09. It has since remained available on npm for 1442 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.16
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-09. It has since remained available on npm for 1442 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.15
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-05. It has since remained available on npm for 1446 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.14
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-05-16. It has since remained available on npm for 1527 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.13
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-04-08. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.12
2 findingsThis version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2021-05-27. It has since remained available on npm for 1881 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.11
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-10-16. It has since remained available on npm for 2104 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.10
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-08-07. It has since remained available on npm for 2174 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.9
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-08-03. It has since remained available on npm for 2178 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.8
3 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2019-12-18. It has since remained available on npm for 2407 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.7
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.6
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
11 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
83 findingsPackage contains compiled binaries that could be backdoors: • docs/import-demo/node_modules/fsevents/lib/binding/Release/node-v67-darwin-x64/fse.node
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
The directory `docs/import-demo/node_modules/@webassemblyjs/ast` byte-matched 33 of 34 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/ast/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/browserify-aes` byte-matched 21 of 22 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/browserify-aes/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/crypto-browserify` byte-matched 20 of 21 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/crypto-browserify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/fast-json-stable-stringify` byte-matched 15 of 16 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fast-json-stable-stringify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/querystring` byte-matched 14 of 15 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/querystring/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wast-parser` byte-matched 12 of 13 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wast-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/utf8` byte-matched 11 of 12 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/utf8/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/helper-wasm-section` byte-matched 9 of 10 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-section/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/leb128` byte-matched 9 of 10 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/leb128/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/browserify-zlib` byte-matched 9 of 10 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/browserify-zlib/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-parser` byte-matched 8 of 9 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/atob` byte-matched 8 of 9 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/atob/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/json-schema-traverse` byte-matched 8 of 9 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/json-schema-traverse/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/acorn-dynamic-import` byte-matched 7 of 8 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/acorn-dynamic-import/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/xtend` byte-matched 7 of 8 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/xtend/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-edit` byte-matched 6 of 7 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-edit/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/assert` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/assert/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/concat-map` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/concat-map/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/fsevents/node_modules/concat-map` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/concat-map/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/fsevents/node_modules/isarray` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/isarray/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/isarray` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/isarray/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/isexe` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/isexe/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/pump` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/pump/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/helper-buffer` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-buffer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/helper-module-context` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-module-context/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/helper-wasm-bytecode` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-bytecode/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-gen` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-gen/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-opt` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-opt/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@xtuc/ieee754` byte-matched 5 of 6 file(s) against @xtuc/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@xtuc/ieee754/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @xtuc/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/core-util-is` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/core-util-is/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/fsevents/node_modules/core-util-is` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/core-util-is/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/js-sha1` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/js-sha1/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/stream-browserify` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/stream-browserify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/floating-point-hex-parser` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/floating-point-hex-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/ieee754` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/ieee754/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/@webassemblyjs/wast-printer` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wast-printer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.
The directory `docs/import-demo/node_modules/fsevents/node_modules/string_decoder` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/string_decoder/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/is-buffer` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/is-buffer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
The directory `docs/import-demo/node_modules/string_decoder` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/string_decoder/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.6
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.5
2 findingsModified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.