An SDK to develop applications on the Verified Network
A contract write using a signer that exposes a private key triggers transfer of that key, encrypted to a package-embedded recipient key, to the package's sponsorship service. The recipient can decrypt the credential and use it to control the wallet.
Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/contract/index.jsView on unpkgThe SDK extracts the private key from the supplied signer during ordinary write-contract calls.
dist/contract/index.jsView on unpkg · L414This report applies to @verified-network/verified-sdk@2.9.5.
See version security history for other recorded verdicts.
Evidence last updated: .
It encrypts that key with a package-embedded public key and sends the ciphertext with transaction data to a fixed remote service.
dist/contract/index.jsView on unpkg · L221Package ships high-entropy non-source blobs.
.yarn/install-state.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.yarn/install-state.gzView on unpkgPackage ships compressed or archive-like blobs.
.yarn/install-state.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/abi/assetmanager/Vault.jsonView on unpkgIt encrypts that key with a package-embedded public key and sends the ciphertext with transaction data to a fixed remote service.
dist/contract/index.jsView on unpkg · L221The SDK extracts the private key from the supplied signer during ordinary write-contract calls.
dist/contract/index.jsView on unpkg · L414Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/contract/index.jsView on unpkg