registry  /  @feedmepos/mf-inventory-portal  /  1.7.0-dev.6

@feedmepos/mf-inventory-portal@1.7.0-dev.6

⚠ Under review

## Description

Static Scan Results

scanned 5d ago · by rust-scanner

Static analysis flagged 11 finding(s) at 86.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.

Static reason
High-risk behavior combination matched malicious policy.

Decision evidence

public snapshot
Behavioral surface
Source
ChildProcessEvalFilesystemNativeBindingsNetworkShell
Supply chain
HighEntropyStringsMinifiedTelemetryUrlStrings
Manifest
NoLicense
scanned 104 file(s), 9.22 MB of source, external domains: api.github.com, blog.hackers-cafe.net, cdnjs.cloudflare.com, docs.oracle.com, edge.api.flagsmith.com, feature-flag-proxy.feedme.farm, feedme.ai, github.com, jspdf.default.namespaceuri, lodash.com, maps.googleapis.com, npm.pkg.github.com, npms.io, openjsf.org, openoffice.org, opensource.org, purl.oclc.org, purl.org, realtime.flagsmith.com, registry.npmjs.org, schemas.microsoft.com, schemas.openxmlformats.org, sheetjs.com, sheetjs.openxmlformats.org, sms.feedmeapi.com, stuk.github.io, tc39.es, underscorejs.org, webpjs.appspot.com, www.cs.cmu.edu, www.fpdf.org, www.myersdaily.org, www.pakpost.gov.pk, www.phpied.com, www.w3.org, www.yworks.com
Oversized source lightweight scan
dist/app-pfHbU1WT.js4.71 MB file, sampled 256 KB
HighEntropyStrings

Source & flagged code

3 flagged · loading source
dist/jszip.min-D3KgBOLH.jsView file
2265}, d.setImmediate = function(x) { L2266: typeof x != "function" && (x = new Function("" + x)); L2267: for (var E = new Array(arguments.length - 1), B = 0; B < E.length; B++) E[B] = arguments[B + 1];
Low
Eval

Package source references a known benign dynamic code generation pattern.

dist/jszip.min-D3KgBOLH.jsView on unpkg · L2265
dist/IntegrationExplorerView-m340FRkF.jsView file
9157contains invisible/control Unicode U+200B (zero width space) --Ÿ­؜<U+200B><U+200E><U+200F>\u2028\u2029<U+202D><U+202E><U+2066><U+2067><U+2069>\uFEFF-]`, oo), Dp = {
Critical
Trojan Source Unicode

Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.

dist/IntegrationExplorerView-m340FRkF.jsView on unpkg · L9157
dist/app-pfHbU1WT.jsView file
path = dist/app-pfHbU1WT.js kind = oversized_source_file sizeBytes = 4940241 magicHex = [redacted]
High
Oversized Source File

Package contains source files above the static scanner size ceiling.

dist/app-pfHbU1WT.jsView on unpkg

Findings

1 Critical1 High2 Medium7 Low
CriticalTrojan Source Unicodedist/IntegrationExplorerView-m340FRkF.js
HighOversized Source Filedist/app-pfHbU1WT.js
MediumNetwork
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvaldist/jszip.min-D3KgBOLH.js
LowFilesystem
LowHigh Entropy Strings
LowTelemetry
LowUrl Strings
LowNo License