← Home

@teambit/mdx

20
Versions
SEE LICENSE IN UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js AI (source-diff): Webpack chunk loader pattern; network refs are UI library imports, not malicious exfiltration. ai
source-diff net-exec-file:artifacts/env-template/public/peers.756261df050d3e99c4f4.js AI (source-diff): Webpack chunk loader pattern; no malicious network/exec behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.756261df050d3e99c4f4.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.2803be1e66624c3ae364.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.24063bd06a4c56ecf401.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/944.23c7a42c25b29314f834.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff net-exec-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Webpack chunk loader; references are to bit.dev static assets and known npm packages. ai
source-diff obfuscated-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Standard webpack minified bundle in env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/252.3669dedd6628a68e9a63.js AI (source-diff): Standard webpack minified bundle in env-template artifacts; consistent with teambit's build output pattern. ai
source-diff net-exec-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js AI (source-diff): Webpack chunk loader pattern in browser preview bundle; not dropper malware. ai
source-diff net-exec-file:artifacts/env-template/public/peers.73a2a70dc18b1d8e71d5.js AI (source-diff): Webpack chunk loader in browser preview bundle; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.73a2a70dc18b1d8e71d5.js AI (source-diff): Webpack-minified peers bundle containing MDX/React; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.4b46b9c1c4152bb8c985.js AI (source-diff): Webpack-minified overview preview bundle; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.438cedd94ac2177b9dd5.js AI (source-diff): Webpack-minified compositions preview bundle; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/427.4ed003b9ce0af834c6f1.js AI (source-diff): Webpack-minified preview modules bundle; standard Bit build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js AI (source-diff): Webpack chunk loader in browser preview bundle; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/254.848b21663dcb32f9874d.js AI (source-diff): Webpack-minified env-template bundle with Bit workspace config; standard build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/109.8f7b5a48f4130e2d8d5c.js AI (source-diff): Webpack-minified env-template preview bundle; standard Bit build artifact, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js AI (source-diff): Minified MDX/React peers bundle; contains recognizable React and MDX library code. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.1d9cf133c5aed91d403c.js AI (source-diff): Webpack compositions chunk with regenerator-runtime; standard build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/874.3ef824f68e8be46dbe18.js AI (source-diff): Bit preview-modules bundle; minified but contains only preview registry logic. ai
source-diff net-exec-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js AI (source-diff): Webpack chunk; dynamic require is webpack's module system, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js AI (source-diff): Minified floating-ui + React bundle; standard build artifact for this package. ai
source-diff net-exec-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Webpack chunk for Bit env-template UI; network/exec patterns are webpack module loading, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Standard webpack bundle artifact; contains recognizable Bit/pnpm config data, not malicious obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js AI (source-diff): Webpack module loading pattern in peers bundle; not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e5a9d86f138262d8248f.js AI (source-diff): Webpack overview chunk; same pattern as other env-template artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/109.afe99e101a5dd2335ed5.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code, no malicious patterns. ai
source-diff net-exec-file:artifacts/env-template/public/peers.d53e72f98a5b329b689a.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d53e72f98a5b329b689a.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.7d24b9b1b1da5e262611.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.6eb8268f21046aae90cd.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff net-exec-file:artifacts/env-template/public/247.bc23f3269336c972f682.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/247.bc23f3269336c972f682.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff obfuscated-file:artifacts/env-template/public/21.3ce949aa33ff0533d924.js AI (source-diff): Standard webpack-minified UI preview bundle; not install-time code. ai
source-diff net-exec-file:artifacts/env-template/public/109.afe99e101a5dd2335ed5.js AI (source-diff): Webpack chunk loader pattern in browser preview artifact; not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e0d3ce449a7f9203ff0d.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.9257550e2fa7739816e6.js AI (source-diff): Peer-exposure webpack bundle for MDX/React; benign pattern for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.b1913968613b03b7bbae.js AI (source-diff): Standard webpack bundle in build artifacts directory; consistent with teambit's established CI build pattern. ai
dependencies unvetted-dep:@teambit/mdx.modules.mdx-v3-options AI (dependencies): Internal @teambit org dependency; consistent with Bit component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.6ed4e3e819405b9a7fd4.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Network refs and dynamic require are webpack runtime patterns in a UI preview bundle, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.ef24cc09f4751b7b1b80.js AI (source-diff): Webpack-minified env-template chunk; legitimate Bit platform build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.062c9583b439f2b2b5eb.js AI (source-diff): Webpack-minified peers bundle for MDX preview; legitimate Bit platform build artifact. ai
dependencies unvetted-dep:@teambit/compilation.babel-compiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/mdx.compilers.mdx-transpiler AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
dependencies unvetted-dep:@teambit/mdx.generator.mdx-templates AI (dependencies): Internal @teambit org dependency; consistent with package's component ecosystem pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.7b9f6f32612dab58bab5.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.30b56ae1163010055db6.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.aced30df8badbdd7db05.js AI (source-diff): Standard webpack chunk in Teambit's env-template preview build; minification is expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.b6e0764847e828054c2e.js AI (source-diff): Standard webpack-minified peers bundle exposing MDX/React globals for Bit preview. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.4e4ad34a4323fd43d433.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.4330bdfb6f4fccfe70b2.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Network/exec pattern is webpack chunk loading infrastructure, not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Standard webpack-minified preview bundle from Bit's env-template system. ai
source-diff net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Webpack chunk for browser preview; network+exec pattern is normal for bundled React/floating-ui code. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d540430f4886e3784624.js AI (source-diff): Webpack-minified peers bundle exposing MDX/React globals; standard Bit preview artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.7361db96144a51c87dd7.js AI (source-diff): Webpack-minified overview preview chunk; standard Bit build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.0e74eaf69c98639a8a38.js AI (source-diff): Webpack-minified compositions preview chunk; standard Bit build artifact. ai
source-diff net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack chunk; network+exec pattern is normal for bundled Bit preview runtime. ai
source-diff obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack-minified Bit workspace config chunk; benign build artifact. ai
source-diff obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Standard webpack-minified env-template preview artifact from Bit platform build; not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; normal build artifact pattern for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.996dd704600f74efbd9c.js AI (source-diff): Bit peers webpack bundle exposing MDX/React globals; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e8075062d68cc6943352.js AI (source-diff): Bit preview overview webpack bundle; standard minified artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.f3373c8329e4a5918c3e.js AI (source-diff): Bit preview module webpack bundle; standard minified artifact for this package. ai
source-diff net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Webpack chunk with __webpack_require__; normal build artifact for this package. ai
source-diff obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Standard webpack-minified build artifact; floating-ui library bundle, not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Standard webpack-minified build artifact from Bit env-template preview; not obfuscated malware. ai
source-diff net-exec-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Network+exec pattern is webpack chunk loader for browser preview; not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3ef6b90dc602a054aabe.js AI (source-diff): Webpack-bundled peers bundle for MDX preview; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.a886de91d07252076cec.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.8f29dc4eddb40b49c603.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected for teambit env-template public assets. ai
source-diff obfuscated-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for teambit env-template public assets. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires in a webpack bundle artifact; expected pattern for bundled JS environments. ai
phantom-deps phantom-dep:@teambit/typescript.modules.ts-config-mutator AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/helper-plugin-test-runner AI (phantom-deps): Test runner loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@teambit/typescript AI (phantom-deps): Same org scope; used indirectly via Bit aspect system. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dependency; stable false positive for this package. ai
typosquat typosquat.levenshtein:mobx AI (typosquat): Scoped @teambit package; levenshtein match to mobx is a false positive. ai

Versions (showing 20 of 20)

Version Deps Published
1.0.1014 25 / 9
1.0.995 37 / 11
1.0.982 37 / 11
1.0.980 37 / 11
1.0.975 37 / 11
1.0.972 37 / 11
1.0.970 37 / 11
1.0.969 37 / 11
1.0.968 37 / 11
1.0.957 37 / 11
1.0.956 37 / 11
1.0.952 37 / 11
1.0.951 37 / 11
1.0.949 37 / 11
1.0.939 37 / 11
1.0.631 36 / 11
1.0.628 36 / 11
1.0.625 36 / 11
1.0.624 36 / 11
1.0.611 36 / 11

v1.0.1014

10 findings
HIGH New obfuscated file: artifacts/env-template/public/109.afe99e101a5dd2335ed5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/109.afe99e101a5dd2335ed5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/21.3ce949aa33ff0533d924.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/247.bc23f3269336c972f682.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/247.bc23f3269336c972f682.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.6eb8268f21046aae90cd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.7d24b9b1b1da5e262611.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.d53e72f98a5b329b689a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/peers.d53e72f98a5b329b689a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.995

10 findings
HIGH New obfuscated file: artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.f8e013b8b07100a6b8ca.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/874.3ef824f68e8be46dbe18.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/compositions.1d9cf133c5aed91d403c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.e5a9d86f138262d8248f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/peers.3637a78cff56d9c8d7c0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.982

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/271.8983b12775e9c1379e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/271.8983b12775e9c1379e11.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.0e74eaf69c98639a8a38.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.7361db96144a51c87dd7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.d540430f4886e3784624.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.980

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/760.847613853bcbcc911626.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/760.847613853bcbcc911626.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.ef24cc09f4751b7b1b80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.6ed4e3e819405b9a7fd4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.062c9583b439f2b2b5eb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.975

8 findings
HIGH New obfuscated file: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.4330bdfb6f4fccfe70b2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.4e4ad34a4323fd43d433.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.b6e0764847e828054c2e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.972

8 findings
HIGH New obfuscated file: artifacts/env-template/public/372.747516dd003c8cd1f1c0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/372.747516dd003c8cd1f1c0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.f3373c8329e4a5918c3e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.e8075062d68cc6943352.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.996dd704600f74efbd9c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.970

6 findings
HIGH New obfuscated file: artifacts/env-template/public/382.565b03c5d3748e06fc46.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: artifacts/env-template/public/382.565b03c5d3748e06fc46.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: artifacts/env-template/public/compositions.8f29dc4eddb40b49c603.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.a886de91d07252076cec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.3ef6b90dc602a054aabe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.969

4 findings
HIGH New obfuscated file: artifacts/env-template/public/compositions.e0d3ce449a7f9203ff0d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/overview.b1913968613b03b7bbae.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: artifacts/env-template/public/peers.9257550e2fa7739816e6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.957

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.956

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.952

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.951

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.949

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.939

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.631

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.628

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.625

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.624

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.611

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.