← Home

@polkadot/metadata

Helpers to extract information from runtime metadata

48
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

jacogrpolkadotjs

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:bn.js AI (phantom-deps): bn.js is declared as a peer/transitive dep for consumers; not directly imported is expected for this package. ai
source-diff obfuscated-file:v9/static.js AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata (starts with 0x6d657461 = 'meta'). This is the documented purpose of @polkadot/metadata — storing static metadata snapshots. ai
source-diff obfuscated-file:v12/static.js AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. ai
source-diff obfuscated-file:v11/static.js AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. ai
source-diff obfuscated-file:v10/static.js AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. ai
publish-pattern new-deps-added AI (publish-pattern): @polkadot/types-known is a sibling package in the same polkadot-js/api monorepo, pinned to the same version. Not a suspicious third-party dependency. ai
source-diff large-new-source-files AI (source-diff): Large files are versioned static metadata blobs (v9-v12) — expected growth pattern for this package as new Substrate runtime versions are added. ai
source-diff obfuscated-file:v13/static.d.ts AI (source-diff): TypeScript declaration file containing the same SCALE-encoded metadata hex string as a typed constant. Legitimate pattern for this package's versioned metadata distribution. ai
source-diff obfuscated-file:v13/static.js AI (source-diff): Large hex string is SCALE-encoded Substrate blockchain metadata — the core content this package distributes. Pattern matches existing accepted v13/static.cjs and prior versioned static files. ai
source-diff encoded-string-file:v12/static.d.ts AI (source-diff): TypeScript declaration file for the static metadata hex constant. The long string is the typed literal of the SCALE-encoded metadata blob, not a payload. ai
source-diff encoded-string-file:v12/static.cjs AI (source-diff): Long hex string is SCALE-encoded Polkadot runtime metadata (starts with 0x6d657461 = 'meta'). Shipping static metadata blobs as hex is the documented purpose of @polkadot/metadata. ai
source-diff encoded-string-file:v12/static.js AI (source-diff): Same SCALE-encoded Polkadot runtime metadata hex blob as the CJS variant. Expected content for this package's versioned static metadata exports. ai
source-diff obfuscated-file:v13/static.cjs AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. ai
source-diff obfuscated-file:v12/static.cjs AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. ai
source-diff obfuscated-file:v11/static.cjs AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. ai
source-diff obfuscated-file:v10/static.cjs AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. ai
source-diff obfuscated-file:v9/static.cjs AI (source-diff): These are hex-encoded SCALE metadata blobs (Substrate runtime metadata), not obfuscated code. Standard pattern for @polkadot/metadata static snapshots. ai
maintainer-change maintainer-added AI (maintainer-change): Same legitimate org transition from jacogr to polkadotjs. Not a hostile takeover. ai
provenance publisher-changed AI (provenance): Documented org transition from personal account jacogr to polkadotjs org account. polkadotjs has 917 approved packages, confirming legitimacy. ai

Versions (showing 48 of 48)

Version Deps Published
4.17.1 5 / 1
4.16.2 5 / 1
4.16.1 5 / 1
4.15.1 5 / 1
4.14.1 5 / 1
4.13.1 6 / 1
4.12.1 6 / 1
4.11.2 6 / 1
4.11.1 6 / 1
4.10.1 6 / 1
4.9.2 6 / 1
4.8.1 6 / 1
4.7.2 6 / 1
4.7.1 6 / 1
4.6.2 6 / 1
4.6.1 6 / 1
4.5.1 6 / 1
4.4.1 6 / 1
4.3.1 6 / 1
4.2.1 6 / 1
4.1.1 6 / 1
4.0.3 6 / 1
4.0.2 6 / 1
4.0.1 6 / 1
3.11.1 6 / 1
3.10.2 6 / 1
3.10.1 6 / 1
3.9.3 6 / 1
3.9.2 6 / 1
3.9.1 6 / 1
3.8.1 6 / 1
3.7.3 6 / 1
3.7.2 6 / 1
3.7.1 6 / 1
3.6.4 6 / 1
3.6.3 6 / 1
3.6.2 6 / 1
3.6.1 6 / 1
3.5.1 6 / 1
3.4.1 6 / 1
3.3.2 6 / 1
3.3.1 6 / 1
3.2.3 6 / 1
3.2.2 6 / 1
3.2.1 6 / 1
3.1.1 6 / 1
3.0.1 6 / 1
1.7.1 5 / 1

v4.17.1

7 findings
HIGH Publisher changed: jacogr → polkadotjs (on 2021-07-05) provenance

This version was published by a different npm account than previous versions on 2021-07-05. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: v10/static.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.2

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.14.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.13.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.12.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.11.2

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.11.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.10.1

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.9.2

4 findings
HIGH New obfuscated file: v13/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v13/static.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.8.1

2 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.2

4 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.1

4 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.2

4 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.6.1

4 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.5.1

4 findings
HIGH Long encoded string in modified file: v12/static.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: v12/static.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.4.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-04-05) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-04-05. This could indicate a legitimate maintainer transition or an account compromise.

v4.3.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-29. This could indicate a legitimate maintainer transition or an account compromise.

v4.2.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-22. This could indicate a legitimate maintainer transition or an account compromise.

v4.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-15. This could indicate a legitimate maintainer transition or an account compromise.

v4.0.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-08. This could indicate a legitimate maintainer transition or an account compromise.

v4.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-08. This could indicate a legitimate maintainer transition or an account compromise.

v4.0.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-03-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-03-07. This could indicate a legitimate maintainer transition or an account compromise.

v3.11.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-28) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-28. This could indicate a legitimate maintainer transition or an account compromise.

v3.10.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-23) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-23. This could indicate a legitimate maintainer transition or an account compromise.

v3.10.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-22. This could indicate a legitimate maintainer transition or an account compromise.

v3.9.3

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-16) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-16. This could indicate a legitimate maintainer transition or an account compromise.

v3.9.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-15. This could indicate a legitimate maintainer transition or an account compromise.

v3.9.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-14) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-14. This could indicate a legitimate maintainer transition or an account compromise.

v3.8.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-07. This could indicate a legitimate maintainer transition or an account compromise.

v3.7.3

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-02. This could indicate a legitimate maintainer transition or an account compromise.

v3.7.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-02) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-02. This could indicate a legitimate maintainer transition or an account compromise.

v3.7.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-02-01) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-02-01. This could indicate a legitimate maintainer transition or an account compromise.

v3.6.4

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-25. This could indicate a legitimate maintainer transition or an account compromise.

v3.6.3

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-24. This could indicate a legitimate maintainer transition or an account compromise.

v3.6.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-24. This could indicate a legitimate maintainer transition or an account compromise.

v3.6.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-24. This could indicate a legitimate maintainer transition or an account compromise.

v3.5.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-18. This could indicate a legitimate maintainer transition or an account compromise.

v3.4.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-11) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-11. This could indicate a legitimate maintainer transition or an account compromise.

v3.3.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-06) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-06. This could indicate a legitimate maintainer transition or an account compromise.

v3.3.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2021-01-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-01-04. This could indicate a legitimate maintainer transition or an account compromise.

v3.2.3

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2020-12-29) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-29. This could indicate a legitimate maintainer transition or an account compromise.

v3.2.2

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2020-12-28) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-28. This could indicate a legitimate maintainer transition or an account compromise.

v3.2.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2020-12-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-27. This could indicate a legitimate maintainer transition or an account compromise.

v3.1.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2020-12-20) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-20. This could indicate a legitimate maintainer transition or an account compromise.

v3.0.1

6 findings
HIGH New obfuscated file: v10/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v11/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v12/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: v9/static.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jacogr → polkadotjs (on 2020-12-14) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2020-12-14. This could indicate a legitimate maintainer transition or an account compromise.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.