← Home

@rsdoctor/client

This package is the Rsdoctor reporting platform.

27
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yifancongchenjiahan

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/resource/js/rc-1.b43035e064.js AI (source-diff): Bundled rc-* component chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/react.7c49fb5914.js AI (source-diff): False positive on bundled React runtime; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/index.7980e1096f.js AI (source-diff): Bundled app entry chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/diff.73c9bbb75f.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/diff.73c9bbb75f.js AI (source-diff): Bundled diff-view chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.f0e8a5e979.js AI (source-diff): Bundled Ant Design icons chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.7ff8d78249.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.2fdffb4a35.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.10fadcad30.js AI (source-diff): Bundled Ant Design chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.dcacdda382.js AI (source-diff): Bundled Ant Design Modal/Button chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.c6142e8905.js AI (source-diff): Bundled Ant Design component chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/713.4a558b34df.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/713.4a558b34df.js AI (source-diff): Bundled @ant-design/fast-color chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/494.345d38694e.js AI (source-diff): Bundled slick-carousel/slider chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/26.1c2637e740.js AI (source-diff): Bundled Ant Design icon SVG definitions; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/142.350290ccb0.js AI (source-diff): Rspack-bundled React/AntD UI chunks; minification is expected for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.50becc7474.js AI (source-diff): Bundled rc-* component chunk; minified output expected. ai
source-diff net-exec-file:dist/resource/js/index.7980e1096f.js AI (source-diff): False positive on bundled UI code; no real network+exec pattern. ai
source-diff obfuscated-file:dist/resource/js/react.7c49fb5914.js AI (source-diff): Bundled React runtime chunk; minified output expected. ai
source-diff obfuscated-file:dist/resource/js/881.9861e399a5.js AI (source-diff): Minified rspack chunk containing @ant-design/icons; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/681.2b2ee6ceb1.js AI (source-diff): Network+exec pattern fires on bundled Ant Design color/theme code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/681.2b2ee6ceb1.js AI (source-diff): Minified rspack chunk containing @ant-design/fast-color; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/181.39d948030a.js AI (source-diff): Minified rspack chunk containing react-slick slider code; expected build artifact for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.b3ef954307.js AI (source-diff): Minified Ant Design modal/button component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/564.aba3fb731b.js AI (source-diff): Minified rspack chunk containing Rsdoctor app shell code; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/react.cad9d743fd.js AI (source-diff): Pattern fires on bundled React runtime; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/react.cad9d743fd.js AI (source-diff): Minified React runtime bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-1.b442c9d037.js AI (source-diff): Minified rc-* component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-0.1899feb0c1.js AI (source-diff): Minified rc-* component bundle; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/index.b7a23597a1.js AI (source-diff): Pattern fires on bundled app entry code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/index.b7a23597a1.js AI (source-diff): Main rspack entry chunk; expected minified build artifact. ai
source-diff net-exec-file:dist/resource/js/diff.326a80ea66.js AI (source-diff): Pattern fires on bundled diff utility code; no actual dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/diff.326a80ea66.js AI (source-diff): Minified diff-library chunk; expected build artifact for this build-analysis tool. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.56c57bb47f.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.1b59606406.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.90605e10b9.js AI (source-diff): Minified Ant Design component bundle; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.423dc49a53.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff large-new-source-files AI (source-diff): UI client package ships bundled dist; large file count is expected for this package type. ai
source-diff net-exec-file:dist/resource/js/react.a376b049da.js AI (source-diff): Minified React bundle; network+exec pattern is false positive in bundled UI code. ai
source-diff obfuscated-file:dist/resource/js/react.a376b049da.js AI (source-diff): Minified React bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.f953c6a3e4.js AI (source-diff): Minified rc-* component bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.6e1040359f.js AI (source-diff): Minified rc-* component bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.6d735fb087.js AI (source-diff): Minified ant-design-icons bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.a51fff4025.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.864d7e37fa.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.f4524a4f5e.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.3da9e5560d.js AI (source-diff): Minified ant-design bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/70.b88e2c49cf.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/181.202c32f28e.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/630.d98cf14f77.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/681.2f02a25876.js AI (source-diff): Standard rspack-minified frontend bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/681.2f02a25876.js AI (source-diff): Minified React/ant-design UI bundle; network+exec pattern is from bundled fetch/eval in UI framework code. ai
source-diff net-exec-file:dist/resource/js/index.f83e52ca10.js AI (source-diff): Main rspack entry bundle; network+exec pattern is false positive in bundled UI code. ai
source-diff obfuscated-file:dist/resource/js/index.f83e52ca10.js AI (source-diff): Main rspack entry bundle; expected output for this UI package. ai
source-diff net-exec-file:dist/resource/js/diff.55f1533174.js AI (source-diff): Minified diff library; network+exec pattern is false positive in bundled UI code. ai
source-diff obfuscated-file:dist/resource/js/diff.55f1533174.js AI (source-diff): Minified diff library bundle; expected output for this UI package. ai
source-diff obfuscated-file:dist/resource/js/904.9d3c9413.js AI (source-diff): Bundled rsdoctor UI entry; normal minified frontend output. ai
source-diff obfuscated-file:dist/resource/js/vender.897ee4e5.js AI (source-diff): Vendor bundle; normal minified frontend output. ai
source-diff net-exec-file:dist/resource/js/index.d65452dc.js AI (source-diff): Main UI webpack bundle; no actual dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/index.d65452dc.js AI (source-diff): Main UI bundle; normal minified frontend output. ai
source-diff net-exec-file:dist/resource/js/diff.c3f45786.js AI (source-diff): Diff library webpack chunk; no actual dropper pattern. ai
source-diff obfuscated-file:dist/resource/js/diff.c3f45786.js AI (source-diff): Bundled diff library for UI; normal minified frontend output. ai
source-diff obfuscated-file:dist/resource/js/index.7b4ed747.js AI (source-diff): Webpack-bundled app entry; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/vender.3b7dad84.js AI (source-diff): Webpack module loader pattern in vendor bundle; not malware. ai
source-diff obfuscated-file:dist/resource/js/vender.3b7dad84.js AI (source-diff): Minified vendor bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/rc-0.0ea117ca.js AI (source-diff): Minified rc-* component bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/index.7b4ed747.js AI (source-diff): Webpack module loader pattern; not malware. ai
source-diff net-exec-file:dist/resource/js/301.6fe78e8f.js AI (source-diff): Webpack chunk with React/Ant Design code; net+exec pattern is webpack module loader, not malware. ai
source-diff obfuscated-file:dist/resource/js/301.6fe78e8f.js AI (source-diff): Standard webpack-minified frontend bundle; content is legitimate ant-design color utilities. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.fbcb77ae.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.005bd3a7.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/rc-0.0816fdf8.js AI (source-diff): Minified rc-* UI component bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/rc-1.9a056fca.js AI (source-diff): Minified rc-* UI component bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/react.66832997.js AI (source-diff): Minified React bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/react.66832997.js AI (source-diff): React's dynamic module patterns; not malicious. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.6eaab0ba.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/301.29d82550.js AI (source-diff): Webpack chunk with dynamic module loading; expected pattern for bundled SPA assets. ai
source-diff obfuscated-file:dist/resource/js/301.29d82550.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color palette); not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.0c6e16e5.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff obfuscated-file:dist/resource/js/vender.baa75fcf.js AI (source-diff): Minified vendor bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/vender.baa75fcf.js AI (source-diff): Webpack dynamic imports in vendor bundle; not malicious. ai
source-diff net-exec-file:dist/resource/js/index.803dd75a.js AI (source-diff): Webpack dynamic imports in SPA entry; not malicious. ai
source-diff obfuscated-file:dist/resource/js/index.803dd75a.js AI (source-diff): Main webpack entry bundle for SPA; expected minified output. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.fbde6d43.js AI (source-diff): Minified ant-design UI bundle; legitimate frontend asset. ai
source-diff net-exec-file:dist/resource/js/react.e5b2c2b5.js AI (source-diff): React bundle; network/eval patterns are normal React runtime artifacts. ai
source-diff net-exec-file:dist/resource/js/vender.76f83665.js AI (source-diff): Vendor bundle; network/eval patterns are normal bundled library artifacts. ai
source-diff obfuscated-file:dist/resource/js/vender.76f83665.js AI (source-diff): Minified vendor bundle; legitimate bundled dependencies. ai
source-diff obfuscated-file:dist/resource/js/react.e5b2c2b5.js AI (source-diff): Minified React bundle; legitimate and expected. ai
source-diff obfuscated-file:dist/resource/js/rc-1.caad7806.js AI (source-diff): Minified rc-* component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/rc-0.ac891904.js AI (source-diff): Minified rc-* component bundle; legitimate UI library code. ai
source-diff net-exec-file:dist/resource/js/index.c3891998.js AI (source-diff): Browser bundle; network/eval patterns are normal React SPA artifacts. ai
source-diff obfuscated-file:dist/resource/js/index.c3891998.js AI (source-diff): Webpack-bundled app entry; minification is expected for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.a1b962c5.js AI (source-diff): Minified antd-icons bundle with SVG data; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.9f7db830.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.86e745f2.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.0ef4ec77.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.9709b0be.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.5f6e41bd.js AI (source-diff): Minified antd component bundle; legitimate UI library code. ai
source-diff net-exec-file:dist/resource/js/756.9e80a153.js AI (source-diff): Browser webpack chunk; network/eval patterns are normal React/antd bundle artifacts. ai
source-diff obfuscated-file:dist/resource/js/756.9e80a153.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color utilities); not obfuscation. ai
source-diff obfuscated-file:dist/resource/js/339.425781b7.js AI (source-diff): Standard webpack-minified frontend bundle chunk; expected for a client UI package. ai
source-diff obfuscated-file:dist/resource/js/339.2a821d36.js AI (source-diff): Standard webpack-minified bundle chunk; expected for this frontend client package. ai
source-diff obfuscated-file:dist/resource/js/index.0d8b60cf.js AI (source-diff): Main webpack entry bundle for rsdoctor client UI; minification is expected. ai
source-diff net-exec-file:dist/resource/js/index.0d8b60cf.js AI (source-diff): Browser SPA bundle; network+exec pattern is false positive. ai
source-diff obfuscated-file:dist/resource/js/index.c069fd35.js AI (source-diff): Standard webpack entry bundle for rsdoctor client SPA. ai
source-diff net-exec-file:dist/resource/js/index.c069fd35.js AI (source-diff): Frontend SPA bundle; network+exec pattern is normal for browser JS apps. ai
source-diff obfuscated-file:dist/resource/js/339.17957712.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/31.00f60aa6.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/187.54a8d2dc.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/index.9b701719.js AI (source-diff): Main app bundle; minified webpack output, not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.6bf63acc.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.05f36d12.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.3ce1955b.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.c33e6cb4.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/vender.70d6647c.js AI (source-diff): Minified vendor bundle; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.2d9b4e67.js AI (source-diff): Minified rc-* component library chunk; expected for this UI package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.aabb43ad.js AI (source-diff): Minified rc-* component library chunk; expected for this UI package. ai
source-diff net-exec-file:dist/resource/js/index.9b701719.js AI (source-diff): Browser-side fetch+eval patterns in React SPA bundle; not a dropper. ai
source-diff obfuscated-file:dist/resource/js/715.a638a151.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/413.53dc0969.js AI (source-diff): Standard webpack-minified UI bundle chunk; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.0f462273.js AI (source-diff): Minified Ant Design library chunk; expected for this UI package. ai
source-diff net-exec-file:dist/resource/js/vender.70d6647c.js AI (source-diff): Vendor bundle (ant-design/rc components); eval patterns from minified third-party libs. ai
bogus-package bogus-package AI (bogus-package): Legitimate scoped package in a large monorepo; sparse README/keywords are expected. ai
source-diff obfuscated-file:dist/resource/js/react.17aa4f75.js AI (source-diff): Minified React bundle; long lines are standard minification, not obfuscation. ai
source-diff net-exec-file:dist/resource/js/react.17aa4f75.js AI (source-diff): React runtime legitimately uses eval/new Function and XHR; not malware. ai
source-diff obfuscated-file:dist/resource/js/index.a0a1553a.js AI (source-diff): Minified webpack entry bundle for rsdoctor client UI. ai
source-diff net-exec-file:dist/resource/js/index.a0a1553a.js AI (source-diff): Webpack bundle for a build-analysis UI; network+eval patterns are from bundler runtime. ai
source-diff obfuscated-file:dist/resource/js/133.265150e3.js AI (source-diff): Standard webpack-minified frontend bundle (ant-design color utilities); not obfuscation. ai
source-diff net-exec-file:dist/resource/js/133.265150e3.js AI (source-diff): Webpack chunk with dynamic module loading; no malicious network calls evident in samples. ai
source-diff obfuscated-file:dist/resource/js/index.0768c070.js AI (source-diff): Webpack-bundled main entry; standard minification for a frontend client package. ai
source-diff net-exec-file:dist/resource/js/index.0768c070.js AI (source-diff): Webpack dynamic imports in browser bundle; not malicious dropper behavior. ai
source-diff obfuscated-file:dist/resource/js/187.892c5bc9.js AI (source-diff): Standard webpack-minified chunk of a React/ECharts SPA; not obfuscated malware. ai
source-diff obfuscated-file:dist/resource/js/715.beadd8b5.js AI (source-diff): Standard webpack-minified chunk; echarts-for-react component. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.fd736134.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/413.463df149.js AI (source-diff): Standard webpack-minified chunk; ECharts view chart code. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.2e00f600.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.cf9e3262.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.59c4f277.js AI (source-diff): Standard webpack-minified Ant Design chunk. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.1ca4a07e.js AI (source-diff): Standard webpack-minified Ant Design Icons chunk. ai
source-diff obfuscated-file:dist/resource/js/index.b1d41f5e.js AI (source-diff): Main SPA entry bundle; minified React app, not obfuscated malware. ai
source-diff net-exec-file:dist/resource/js/index.b1d41f5e.js AI (source-diff): React SPA fetches build stats data; dynamic require is standard webpack runtime, not dropper. ai
source-diff obfuscated-file:dist/resource/js/rc-0.201d292e.js AI (source-diff): Standard webpack-minified rc-* component chunk. ai
source-diff obfuscated-file:dist/resource/js/rc-1.ad04108d.js AI (source-diff): Standard webpack-minified rc-* component chunk. ai
source-diff obfuscated-file:dist/resource/js/339.d97a5eb5.js AI (source-diff): Standard webpack-minified chunk; contains rsdoctor route/constant definitions. ai
source-diff obfuscated-file:dist/resource/js/31.e37348c3.js AI (source-diff): Standard webpack-minified chunk; ECharts rendering code. ai
source-diff net-exec-file:dist/resource/js/index.5cff221c.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive for this client-side web app package. ai
source-diff obfuscated-file:dist/resource/js/577.10ff2379.js AI (source-diff): Standard webpack-minified UI bundle (ant-design icons chunk). ai
source-diff obfuscated-file:dist/resource/js/601.dc26c158.js AI (source-diff): Standard webpack-minified UI bundle for rsdoctor client. ai
source-diff obfuscated-file:dist/resource/js/641.c0cd2597.js AI (source-diff): Standard webpack-minified UI bundle (slick carousel chunk). ai
source-diff net-exec-file:dist/resource/js/react.f1c1c97a.js AI (source-diff): Network+exec pattern in webpack React bundle is false positive for this client-side web app package. ai
source-diff net-exec-file:dist/resource/js/diff.6498e93a.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive for this client-side web app package. ai
source-diff net-exec-file:dist/resource/js/383.2e75ce49.js AI (source-diff): Network+exec pattern in webpack UI bundle is false positive; no actual fetch+eval pattern visible in sample. ai
source-diff obfuscated-file:dist/resource/js/react.f1c1c97a.js AI (source-diff): Standard webpack-minified React bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-1.08d0910e.js AI (source-diff): Standard webpack-minified rc-component bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-0.f5bcb33d.js AI (source-diff): Standard webpack-minified rc-component bundle. ai
source-diff obfuscated-file:dist/resource/js/index.5cff221c.js AI (source-diff): Standard webpack-minified main entry bundle for rsdoctor client UI. ai
source-diff obfuscated-file:dist/resource/js/diff.6498e93a.js AI (source-diff): Standard webpack-minified diff library bundle for rsdoctor client UI. ai
source-diff obfuscated-file:dist/resource/js/383.2e75ce49.js AI (source-diff): Standard webpack-minified UI bundle for rsdoctor client; minification is expected for this package. ai
source-diff net-exec-file:dist/resource/js/709.d24e2ffb.js AI (source-diff): Webpack bundle with fetch/dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/709.d24e2ffb.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/702.19a48c2a.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact for this frontend client package. ai
source-diff obfuscated-file:dist/resource/js/904.ecbb2c06.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.71243426.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.6050f2c5.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.16432452.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.23ce91b6.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.97833ea2.js AI (source-diff): Minified ant-design bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.6f529e48.js AI (source-diff): Minified ant-design-icons bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/diff.e7ce9b7c.js AI (source-diff): Minified diff library bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/diff.e7ce9b7c.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/vender.9840e009.js AI (source-diff): Minified vendor bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/react.419e5c4a.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/index.e62055d7.js AI (source-diff): Minified main bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/react.419e5c4a.js AI (source-diff): Minified React bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-1.eb2754d2.js AI (source-diff): Minified rc-* bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/rc-0.327357c3.js AI (source-diff): Minified rc-* bundle chunk; expected build artifact. ai
source-diff net-exec-file:dist/resource/js/index.e62055d7.js AI (source-diff): Webpack bundle with dynamic module loading; not dropper malware. ai
source-diff obfuscated-file:dist/resource/js/736.04fd2dc8.js AI (source-diff): Standard webpack-minified bundle chunk; expected build artifact. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.f6718859.js AI (source-diff): Standard webpack-minified ant-design-icons bundle. ai
publish-pattern dormant-publish AI (publish-pattern): Version gap matches legitimate v1.1.x→v1.2.x release cycle for rsdoctor monorepo. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA provenance is expected for this monorepo. ai
source-diff net-exec-file:dist/resource/js/vender.0a509a76.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/react.3416b75d.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/index.dd8eb261.js AI (source-diff): Browser webpack chunk; net-exec pattern is false positive for browser UI bundle. ai
source-diff net-exec-file:dist/resource/js/304.aa917bbe.js AI (source-diff): Browser webpack chunk; fetch+dynamic patterns are normal in bundled browser UI code. ai
source-diff obfuscated-file:dist/resource/js/vender.0a509a76.js AI (source-diff): Standard webpack-minified vendor bundle. ai
source-diff obfuscated-file:dist/resource/js/react.3416b75d.js AI (source-diff): Standard webpack-minified React bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-1.a0853e1e.js AI (source-diff): Standard webpack-minified rc-* bundle. ai
source-diff obfuscated-file:dist/resource/js/rc-0.93ad3cb8.js AI (source-diff): Standard webpack-minified rc-* bundle. ai
source-diff obfuscated-file:dist/resource/js/index.dd8eb261.js AI (source-diff): Standard webpack-minified main entry bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.fc287b65.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.e823b890.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.748849f0.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.32845f6f.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.c067cf25.js AI (source-diff): Standard webpack-minified ant-design bundle. ai
source-diff obfuscated-file:dist/resource/js/304.aa917bbe.js AI (source-diff): Standard webpack-minified ant-design/react bundle; not obfuscation. ai
source-diff net-exec-file:dist/resource/js/react.9f38b670.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/vender.77ed69e7.js AI (source-diff): Minified vendor bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/vender.77ed69e7.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/6.443c6bd9.js AI (source-diff): Standard webpack-minified browser bundle; content is recognizable Ant Design color utilities. ai
source-diff obfuscated-file:dist/resource/js/react.9f38b670.js AI (source-diff): Minified React bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-2.a9ba63e5.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-1.be16b817.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/rc-0.7f6c32e1.js AI (source-diff): Minified rc-* component bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/index.3448b987.js AI (source-diff): webpack chunk loading in browser SPA; not malware. ai
source-diff obfuscated-file:dist/resource/js/index.3448b987.js AI (source-diff): Minified webpack entry bundle for SPA; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-icons.ae049bf7.js AI (source-diff): Minified Ant Design icons bundle; SVG icon data clearly visible in sample. ai
source-diff obfuscated-file:dist/resource/js/ant-design-4.1134e91c.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-3.f0a5055d.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-2.990bb762.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-1.afd634fc.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff obfuscated-file:dist/resource/js/ant-design-0.8a716a60.js AI (source-diff): Minified Ant Design component bundle; normal for this client package. ai
source-diff net-exec-file:dist/resource/js/6.443c6bd9.js AI (source-diff): webpack chunk loading pattern in browser SPA bundle; not dropper behavior. ai

Versions (showing 27 of 27)

Version Deps Published
1.5.12 0 / 19
1.5.11 0 / 19
1.5.10 0 / 19
1.5.9 0 / 19
1.5.8 0 / 19
1.5.7 0 / 19
1.5.6 0 / 19
1.3.3 0 / 19
1.3.2 0 / 19
1.3.1 0 / 19
1.3.0 0 / 19
1.2.3 0 / 19
1.2.2 0 / 19
1.2.1 0 / 19
1.2.0 0 / 19
1.1.11 0 / 19
1.1.10 0 / 19
1.1.9 0 / 19
1.1.8 0 / 19
1.1.7 0 / 19
1.1.6 0 / 19
1.1.5 0 / 19
1.1.4 0 / 19
1.1.3 0 / 19
1.1.2 0 / 19
1.1.1 0 / 19
1.1.0 0 / 19

v1.5.12

20 findings
HIGH New obfuscated file: dist/resource/js/142.350290ccb0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/26.1c2637e740.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/494.345d38694e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/713.4a558b34df.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/713.4a558b34df.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.c6142e8905.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.dcacdda382.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.10fadcad30.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.2fdffb4a35.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.7ff8d78249.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f0e8a5e979.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.73c9bbb75f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.73c9bbb75f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.7980e1096f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.7980e1096f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.50becc7474.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.b43035e064.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.7c49fb5914.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.7c49fb5914.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.11

20 findings
HIGH New obfuscated file: dist/resource/js/181.39d948030a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/564.aba3fb731b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/681.2b2ee6ceb1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/681.2b2ee6ceb1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/881.9861e399a5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.b3ef954307.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.90605e10b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.1b59606406.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.864d7e37fa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.56c57bb47f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6d735fb087.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.326a80ea66.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.326a80ea66.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.b7a23597a1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.b7a23597a1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.1899feb0c1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.b442c9d037.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.cad9d743fd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.cad9d743fd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.10

20 findings
HIGH New obfuscated file: dist/resource/js/181.202c32f28e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/630.d98cf14f77.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/681.2f02a25876.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/681.2f02a25876.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/70.b88e2c49cf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.423dc49a53.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.3da9e5560d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.f4524a4f5e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.864d7e37fa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.a51fff4025.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6d735fb087.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.55f1533174.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.55f1533174.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.f83e52ca10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.f83e52ca10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.6e1040359f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.f953c6a3e4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.a376b049da.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.a376b049da.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.8

21 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2026-04-14) provenance

This version was published by a different npm account than previous versions on 2026-04-14. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/383.2e75ce49.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/383.2e75ce49.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/577.10ff2379.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/601.dc26c158.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/641.c0cd2597.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.71243426.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.6050f2c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.16432452.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.23ce91b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.97833ea2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6f529e48.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.6498e93a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.6498e93a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.5cff221c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.5cff221c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.f5bcb33d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.08d0910e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.f1c1c97a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.f1c1c97a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.7

22 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2026-03-31) provenance

This version was published by a different npm account than previous versions on 2026-03-31. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/702.19a48c2a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/709.d24e2ffb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/709.d24e2ffb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/736.04fd2dc8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/904.9d3c9413.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.71243426.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.6050f2c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.16432452.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.23ce91b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.97833ea2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6f529e48.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.c3f45786.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.c3f45786.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.d65452dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.d65452dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.327357c3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.eb2754d2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.419e5c4a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.419e5c4a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.897ee4e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.6

22 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2026-03-30) provenance

This version was published by a different npm account than previous versions on 2026-03-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/702.19a48c2a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/709.d24e2ffb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/709.d24e2ffb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/736.04fd2dc8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/904.ecbb2c06.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.71243426.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.6050f2c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.16432452.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.23ce91b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.97833ea2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.6f529e48.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/diff.e7ce9b7c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/diff.e7ce9b7c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/index.e62055d7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.e62055d7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.327357c3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.eb2754d2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.419e5c4a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.419e5c4a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.9840e009.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.3

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-10-15) provenance

This version was published by a different npm account than previous versions on 2025-10-15. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/756.9e80a153.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/756.9e80a153.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.5f6e41bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.9709b0be.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.0ef4ec77.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.86e745f2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.9f7db830.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a1b962c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.c3891998.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.c3891998.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.ac891904.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.caad7806.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.e5b2c2b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.e5b2c2b5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.76f83665.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.76f83665.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-10-11) provenance

This version was published by a different npm account than previous versions on 2025-10-11. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/301.6fe78e8f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/301.6fe78e8f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.5f6e41bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.9709b0be.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.0ef4ec77.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.86e745f2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.9f7db830.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a1b962c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.7b4ed747.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.7b4ed747.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.0ea117ca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.caad7806.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.e5b2c2b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.e5b2c2b5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.3b7dad84.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.3b7dad84.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-09-28) provenance

This version was published by a different npm account than previous versions on 2025-09-28. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/301.29d82550.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/301.29d82550.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6eaab0ba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.fbde6d43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.0c6e16e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.005bd3a7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fbcb77ae.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a1b962c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.803dd75a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.803dd75a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.0816fdf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.9a056fca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.66832997.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.66832997.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.baa75fcf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.baa75fcf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-09-26) provenance

This version was published by a different npm account than previous versions on 2025-09-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/301.29d82550.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/301.29d82550.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6eaab0ba.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.fbde6d43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.0c6e16e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.005bd3a7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fbcb77ae.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.a1b962c5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.803dd75a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.803dd75a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.0816fdf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.9a056fca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.66832997.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.66832997.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.baa75fcf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.baa75fcf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-08-20) provenance

This version was published by a different npm account than previous versions on 2025-08-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/133.265150e3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/133.265150e3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.c067cf25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.32845f6f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.748849f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.e823b890.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fc287b65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.0768c070.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.0768c070.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.93ad3cb8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.a0853e1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.3416b75d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.3416b75d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.0a509a76.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.0a509a76.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.2

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-08-12) provenance

This version was published by a different npm account than previous versions on 2025-08-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/133.265150e3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/133.265150e3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.c067cf25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.32845f6f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.748849f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.e823b890.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fc287b65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.c069fd35.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.c069fd35.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.93ad3cb8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.a0853e1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.3416b75d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.3416b75d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.0a509a76.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.0a509a76.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-08-08) provenance

This version was published by a different npm account than previous versions on 2025-08-08. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/304.aa917bbe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/304.aa917bbe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.c067cf25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.32845f6f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.748849f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.e823b890.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fc287b65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.dd8eb261.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.dd8eb261.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.93ad3cb8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.a0853e1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.3416b75d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.3416b75d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.0a509a76.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.0a509a76.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

18 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-08-07) provenance

This version was published by a different npm account than previous versions on 2025-08-07. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/304.aa917bbe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/304.aa917bbe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.c067cf25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.32845f6f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.748849f0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.e823b890.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.fc287b65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.0d8b60cf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.0d8b60cf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.93ad3cb8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.a0853e1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.3416b75d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.3416b75d.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.0a509a76.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.0a509a76.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.11

21 findings
HIGH Publisher changed: chenjiahan → GitHub Actions (on 2025-08-06) provenance

This version was published by a different npm account than previous versions on 2025-08-06. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.2a821d36.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.a0a1553a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.a0a1553a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.10

20 findings
HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.2a821d36.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.a0a1553a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.a0a1553a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

20 findings
HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.17957712.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.9b701719.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.9b701719.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

20 findings
HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.17957712.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.9b701719.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.9b701719.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

20 findings
HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.17957712.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.9b701719.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.9b701719.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

20 findings
HIGH New obfuscated file: dist/resource/js/187.54a8d2dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.00f60aa6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.425781b7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.53dc0969.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.a638a151.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.6bf63acc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.05f36d12.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.3ce1955b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.c33e6cb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.0f462273.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.f6718859.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.9b701719.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.9b701719.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.aabb43ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.2d9b4e67.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.17aa4f75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.17aa4f75.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.70d6647c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.70d6647c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

20 findings
HIGH New obfuscated file: dist/resource/js/187.892c5bc9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/31.e37348c3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/339.d97a5eb5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/413.463df149.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/715.beadd8b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-0.8a716a60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.fd736134.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.2e00f600.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.cf9e3262.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.59c4f277.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.1ca4a07e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.b1d41f5e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.b1d41f5e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.201d292e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.ad04108d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.9f38b670.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.9f38b670.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.77ed69e7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.77ed69e7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

18 findings
HIGH New obfuscated file: dist/resource/js/6.443c6bd9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/6.443c6bd9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/ant-design-0.8a716a60.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-1.afd634fc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-2.990bb762.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-3.f0a5055d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-4.1134e91c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/ant-design-icons.ae049bf7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/index.3448b987.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/index.3448b987.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/rc-0.7f6c32e1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-1.be16b817.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/rc-2.a9ba63e5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/resource/js/react.9f38b670.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/react.9f38b670.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/resource/js/vender.77ed69e7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resource/js/vender.77ed69e7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.