← Home

@elliemae/ssf-guest

45
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

encw.dev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/public/js/emuiSsfGuest.2c0dd905549c415d0436.js AI (source-diff): Network+exec pattern in a webpack bundle is normal for a browser UI library; no dropper indicators in the sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.2c0dd905549c415d0436.js AI (source-diff): Standard webpack minified bundle with source map; lodash and UMD wrapper visible in sample. Expected artifact for this package. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.1da095cbf5ef6d6e8eff.js AI (source-diff): Network+exec pattern in a browser bundle is expected for a micro-frontend guest library; no dropper indicators in the sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.1da095cbf5ef6d6e8eff.js AI (source-diff): Standard webpack minified browser bundle with source map; lodash and UMD wrapper clearly visible. Not obfuscation. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.e99886cbe40633f2c47a.js AI (source-diff): Webpack-minified frontend bundle with source map; standard build output for this package. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.e99886cbe40633f2c47a.js AI (source-diff): Network+exec pattern in a browser bundle is expected; no dropper behavior visible in the sample. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.768b3c94645989a386e5.js AI (source-diff): Network+exec pattern in a webpack bundle is expected for a micro-frontend guest library; no dropper indicators in the sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.768b3c94645989a386e5.js AI (source-diff): Standard webpack minified bundle with lodash license header; not obfuscated malware. Stable pattern for this package. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.879acb4ec59d72fff625.js AI (source-diff): Function('return this') is lodash globalThis polyfill; not a dropper/loader pattern. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.879acb4ec59d72fff625.js AI (source-diff): Standard webpack UMD bundle; lodash/utility patterns, no malicious code. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.47c94d8a6fa51e37cd64.js AI (source-diff): Standard webpack minified bundle with source map; expected build output for this frontend library. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.47c94d8a6fa51e37cd64.js AI (source-diff): Network+exec pattern is from webpack UMD wrapper and lodash utilities; not dropper behavior. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.b9cd82e624485fd26fb8.js AI (source-diff): Network+exec pattern in a webpack bundle is expected for a micro-frontend guest library; no dropper indicators. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.b9cd82e624485fd26fb8.js AI (source-diff): Standard webpack minified bundle with visible lodash source; not obfuscated malware. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.bb7f9a5114e5717cda3d.js AI (source-diff): Network+exec pattern is webpack module system boilerplate (Function('return this')); not a dropper. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.bb7f9a5114e5717cda3d.js AI (source-diff): Standard webpack bundle with content-hash filename; lodash/UMD patterns visible, no malicious code. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.44b45a086e236e3ba581.js AI (source-diff): Network+exec pattern fires on webpack bundle internals; no actual dropper behavior present. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.44b45a086e236e3ba581.js AI (source-diff): Standard webpack minified bundle with lodash; not obfuscated malware. Pattern is stable for this package. ai
source-diff obfuscated-file:dist/umd/e2e-guest.js AI (source-diff): Same minified e2e test harness as dist/public variant. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.2ad9d47b0f9483ff7095.js AI (source-diff): Standard webpack UMD bundle; minification is expected for this package. ai
source-diff obfuscated-file:dist/public/e2e-guest.js AI (source-diff): Standard minified e2e test harness; not obfuscated malware. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.2ad9d47b0f9483ff7095.js AI (source-diff): Dynamic code execution is Function('return this')() globalThis polyfill in webpack bundle; not malicious. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.e058aa48d90db357a043.js AI (source-diff): Standard webpack minified bundle with source map; consistent with this package's build pipeline across versions. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.e058aa48d90db357a043.js AI (source-diff): Network calls and dynamic requires are part of the UMD module loader pattern in the webpack bundle, not dropper behavior. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.7e429f5c48eb31adf9ac.js AI (source-diff): Network+eval pattern in webpack UMD bundle is a false positive for this package's normal build artifacts. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.7e429f5c48eb31adf9ac.js AI (source-diff): Standard webpack bundle output for this corporate UI library; minification is expected across all versions. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.60315897b4b299913718.js AI (source-diff): Network+exec pattern in a webpack bundle is expected for a micro-frontend guest library; no dropper indicators. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.60315897b4b299913718.js AI (source-diff): Standard webpack minified bundle with lodash; not obfuscated malware. Pattern stable for this package. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.0b1594ea1045aef9f993.js AI (source-diff): Standard webpack minified bundle; lodash and UMD wrapper clearly visible in sample. Expected for this package. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.0b1594ea1045aef9f993.js AI (source-diff): Network+exec pattern in a webpack bundle is normal for a browser guest library; no dropper indicators in sample. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.8402b07b7960210b16bf.js AI (source-diff): Network+exec pattern fires on normal webpack bundle; no dropper behavior evident in sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.8402b07b7960210b16bf.js AI (source-diff): Standard webpack minified bundle with lodash; not obfuscated malware. Stable pattern for this package. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.978ed50e66c23bc975cd.js AI (source-diff): Standard webpack bundle with visible lodash source; minification is expected for this package's dist output. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.978ed50e66c23bc975cd.js AI (source-diff): Network+exec pattern in a webpack bundle is normal for a browser guest library; no dropper indicators in the sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.6a4579277563c043d276.js AI (source-diff): Standard webpack bundle with lodash; minified output is expected for this package's build pipeline. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.6a4579277563c043d276.js AI (source-diff): UMD bundle pattern with network calls is normal for this SSF guest library; not dropper behavior. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.dc017a38b78ac30a1aa3.js AI (source-diff): Standard webpack minified bundle with source map; consistent with this package's established build pattern. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.dc017a38b78ac30a1aa3.js AI (source-diff): UMD bundle with network calls is expected for a micro-frontend guest library; no dropper behavior present. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.386bd3b249e7baa53c5a.js AI (source-diff): Network/exec pattern is from UMD wrapper + lodash utilities in a minified bundle, not dropper behavior. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.386bd3b249e7baa53c5a.js AI (source-diff): Standard webpack minified bundle with source map; consistent with this package's build output pattern. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.650afabac7fe99fb3a5b.js AI (source-diff): Standard webpack bundle for an established Ellie Mae library; minification is expected build output. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.650afabac7fe99fb3a5b.js AI (source-diff): UMD bundle pattern with network calls is normal for this ICE MT SSF guest library; no dropper behavior evident. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.70d35ed24daaaae84bd5.js AI (source-diff): UMD bundle pattern; network+exec pattern is from bundled library code, not malware. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.70d35ed24daaaae84bd5.js AI (source-diff): Standard webpack bundle with lodash; minification is expected for this dist artifact. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.ee124e1dde329168b45d.js AI (source-diff): Standard webpack minified bundle for a frontend library; long lines are expected build output, not obfuscation. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.ee124e1dde329168b45d.js AI (source-diff): Heuristic fires on normal bundled XHR + function calls in a frontend library; no actual dropper behavior present. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.7eac030a329ee1e7f98f.js AI (source-diff): Network+exec pattern in a browser bundle is normal for a micro-frontend guest library; no dropper indicators in the sample. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.7eac030a329ee1e7f98f.js AI (source-diff): Standard webpack minified bundle with source map; lodash and UMD wrapper visible in sample. Expected artifact for this frontend library. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.f5b295c7f5ba9c71436b.js AI (source-diff): Network+eval pattern in a webpack bundle is expected for this micro-frontend library; no malicious payload visible. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.f5b295c7f5ba9c71436b.js AI (source-diff): Standard webpack bundle with identifiable lodash source; minification is expected for this frontend library. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.717e29ef28e37af46c23.js AI (source-diff): UMD bundle with dynamic require; no malicious network+exec pattern, just standard module loading. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.717e29ef28e37af46c23.js AI (source-diff): Minified webpack bundle with source map; standard build artifact for this package. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.bb29d41c0e22d4dc6455.js AI (source-diff): Standard webpack minified bundle with lodash license header; not obfuscated malware. Pattern is stable for this package. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.bb29d41c0e22d4dc6455.js AI (source-diff): Network+exec pattern fires on webpack bundle's UMD wrapper; expected for a browser guest library, not a dropper. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.3aeb730fdd1156849f23.js AI (source-diff): Standard webpack minified bundle with visible lodash license header; not obfuscated malware. ai
phantom-deps phantom-dep:@elliemae/pui-logrocket AI (phantom-deps): Same-org dep; may be used indirectly via bundled dist rather than direct import. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.3aeb730fdd1156849f23.js AI (source-diff): Network+exec pattern in a webpack bundle is expected for a guest library; no dropper indicators in sample. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.96a061c4db53d98ae977.js AI (source-diff): Network+eval pattern is from webpack module loader boilerplate, not dropper malware. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.96a061c4db53d98ae977.js AI (source-diff): Standard webpack minified bundle with lodash; long lines are expected build output for this package. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.8a0d46ec8fe865ab60ed.js AI (source-diff): Standard webpack minified bundle with source map; lodash and UMD wrapper clearly visible. Not obfuscation. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.8a0d46ec8fe865ab60ed.js AI (source-diff): Network+exec pattern in a frontend bundle is expected; no dropper behavior visible in sample. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.f079c1af6182dca7c93f.js AI (source-diff): Network+eval pattern in a webpack bundle is a false positive for this package; no malicious payload evident. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.f079c1af6182dca7c93f.js AI (source-diff): Standard webpack bundle for an established ICE/Ellie Mae library; minification is expected across all versions. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.89e5afb8f3f4bc7225e1.js AI (source-diff): Network+exec pattern fires on UMD bundle boilerplate; no actual dropper behavior present. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.89e5afb8f3f4bc7225e1.js AI (source-diff): Standard webpack minified bundle from an established ICE/Ellie Mae build pipeline; not obfuscation. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.965b40481782717c67fc.js AI (source-diff): Standard webpack minified bundle with UMD wrapper; not obfuscation. Pattern is stable for this package's build output. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.965b40481782717c67fc.js AI (source-diff): Network+exec pattern fires on webpack bundle boilerplate (UMD require/define); no actual dropper behavior present. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.5e336ff598fec26bbf3c.js AI (source-diff): Network+exec pattern is from UMD/webpack boilerplate, not dropper code. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.5e336ff598fec26bbf3c.js AI (source-diff): Standard webpack bundle output; minified dist files are expected for this package. ai
source-diff obfuscated-file:dist/public/js/emuiSsfGuest.c7cb2a470c4afce20567.js AI (source-diff): Standard webpack minified bundle output; content is recognizable lodash/utility code with UMD wrapper. ai
source-diff net-exec-file:dist/public/js/emuiSsfGuest.c7cb2a470c4afce20567.js AI (source-diff): Network+exec pattern in a browser bundle is expected for a micro-frontend guest library; no dropper indicators in sample. ai
bogus-package bogus-package AI (bogus-package): Internal enterprise library; sparse README and no keywords are expected for org-scoped packages. ai

Versions (showing 45 of 45)

Version Deps Published
2.28.6 3 / 3
2.28.5 3 / 3
2.28.4 3 / 3
2.28.3 3 / 3
2.28.2 3 / 3
2.28.1 3 / 3
2.28.0 3 / 3
2.27.0 3 / 3
2.26.0 3 / 3
2.25.3 3 / 3
2.25.2 3 / 3
2.25.1 3 / 3
2.25.0 3 / 3
2.24.0 3 / 3
2.23.7 3 / 3
2.23.6 3 / 3
2.23.4 3 / 3
2.23.2 3 / 3
2.23.1 3 / 3
2.23.0 3 / 3
2.22.3 3 / 3
2.22.2 3 / 3
2.22.1 3 / 3
2.22.0 3 / 3
2.21.4 3 / 3
2.21.3 3 / 3
2.21.2 4 / 4
2.21.1 4 / 4
2.21.0 4 / 4
2.20.3 4 / 4
2.20.2 4 / 4
2.19.2 3 / 3
2.19.1 3 / 3
2.19.0 3 / 3
2.18.1 3 / 3
2.18.0 3 / 3
2.17.9 3 / 3
2.17.8 3 / 3
2.17.5 3 / 3
2.17.4 3 / 3
2.17.3 3 / 3
2.17.2 3 / 3
2.17.1 3 / 3
2.17.0 3 / 3
2.16.6 3 / 3

v2.28.6

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.ee124e1dde329168b45d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.ee124e1dde329168b45d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.5

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.7e429f5c48eb31adf9ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.7e429f5c48eb31adf9ac.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.4

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.386bd3b249e7baa53c5a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.386bd3b249e7baa53c5a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.3

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.717e29ef28e37af46c23.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.717e29ef28e37af46c23.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.5e336ff598fec26bbf3c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.5e336ff598fec26bbf3c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.1

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.89e5afb8f3f4bc7225e1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.89e5afb8f3f4bc7225e1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.965b40481782717c67fc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.965b40481782717c67fc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.27.0

5 findings
HIGH New obfuscated file: dist/public/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/umd/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/public/js/emuiSsfGuest.879acb4ec59d72fff625.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.879acb4ec59d72fff625.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.26.0

5 findings
HIGH New obfuscated file: dist/public/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/umd/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/public/js/emuiSsfGuest.2ad9d47b0f9483ff7095.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.2ad9d47b0f9483ff7095.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.3

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.c7cb2a470c4afce20567.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.c7cb2a470c4afce20567.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.f079c1af6182dca7c93f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.f079c1af6182dca7c93f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.24.0

5 findings
HIGH New obfuscated file: dist/public/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/umd/e2e-guest.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/public/js/emuiSsfGuest.bb7f9a5114e5717cda3d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.bb7f9a5114e5717cda3d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.23.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.23.6

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.650afabac7fe99fb3a5b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.650afabac7fe99fb3a5b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.23.4

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.dc017a38b78ac30a1aa3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.dc017a38b78ac30a1aa3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.23.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.23.1

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.47c94d8a6fa51e37cd64.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.47c94d8a6fa51e37cd64.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.23.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.e058aa48d90db357a043.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.e058aa48d90db357a043.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.22.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.22.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.8402b07b7960210b16bf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.8402b07b7960210b16bf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.22.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.22.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.60315897b4b299913718.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.60315897b4b299913718.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.4

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.7eac030a329ee1e7f98f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.7eac030a329ee1e7f98f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.3

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.b9cd82e624485fd26fb8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.b9cd82e624485fd26fb8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.f5b295c7f5ba9c71436b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.f5b295c7f5ba9c71436b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.1

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.0b1594ea1045aef9f993.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.0b1594ea1045aef9f993.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.21.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.70d35ed24daaaae84bd5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.70d35ed24daaaae84bd5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.20.3

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.3aeb730fdd1156849f23.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.3aeb730fdd1156849f23.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.20.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.978ed50e66c23bc975cd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.978ed50e66c23bc975cd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.19.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.19.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.19.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.bb29d41c0e22d4dc6455.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.bb29d41c0e22d4dc6455.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.18.0

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.1da095cbf5ef6d6e8eff.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.1da095cbf5ef6d6e8eff.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.9

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.44b45a086e236e3ba581.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.44b45a086e236e3ba581.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.8

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.2c0dd905549c415d0436.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.2c0dd905549c415d0436.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.5

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.e99886cbe40633f2c47a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.e99886cbe40633f2c47a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.4

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.6a4579277563c043d276.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.6a4579277563c043d276.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.3

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.96a061c4db53d98ae977.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.96a061c4db53d98ae977.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.2

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.768b3c94645989a386e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.768b3c94645989a386e5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.1

3 findings
HIGH New obfuscated file: dist/public/js/emuiSsfGuest.8a0d46ec8fe865ab60ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/public/js/emuiSsfGuest.8a0d46ec8fe865ab60ed.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.16.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.