Resuable front end components
No attack was identified. The package is a front-end GUI bundle with no install lifecycle and no credential, shell, or exfiltration behavior in the inspected entry.
The AI recommended clean. Static policy retained a warning. A high or critical static finding has no usable source path. These conditions do not mean that the AI confirmed malicious behavior.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.obf.jsView on unpkg · L1The obfuscated entry string table is GUI and CSS text plus a public CodeMirror CDN URL; searches found no eval, Function, fetch, child_process, cookies, or environment harvesting.
dist/index.obf.jsView on unpkg · L1package.json publishes dist/index.obf.js as main and module and defines only local build, test, lint, and setup scripts, with no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L4package.json publishes dist/index.obf.js as main and module and defines only local build, test, lint, and setup scripts, with no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L11This report applies to @tomaso909/jsguitools@1.7.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.obf.jsView on unpkg · L1The obfuscated entry string table is GUI and CSS text plus a public CodeMirror CDN URL; searches found no eval, Function, fetch, child_process, cookies, or environment harvesting.
dist/index.obf.jsView on unpkg · L1package.json publishes dist/index.obf.js as main and module and defines only local build, test, lint, and setup scripts, with no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L4package.json publishes dist/index.obf.js as main and module and defines only local build, test, lint, and setup scripts, with no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L11