PkgRadar

Package evidence

@vultisig/[email protected]

Large Javascript Payload: 2883039 bytes

Trust signals

Why this verdict

PkgRadar discounts a release’s score when public reputation argues against novel malware. The verdict above already reflects these — the panel just explains what was applied.

Weekly downloads
1,752Niche · −30% score
Versions published
78Established · −30% score
First published
Dec 2025
Publisher
rcoderdev

Effective trust discount applied: 30% (max across signals — discounts don’t stack). New install-lifecycle deltas vs the previous release would clear the discount.

Recommended action

Looks clean — keep monitoring

No high-signal indicators in the stored static report. PkgRadar will re-check on the next ingest pass.

Block this release in CIcurl · GitHub Actions

Fail the build when this package version is added or upgraded. Replace $PKGRADAR_TOKEN with a Pro / Team API key from your dashboard.

curl -fsS https://pkgradar.com/gate/npm \
  -H "Authorization: Bearer $PKGRADAR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"specs":["@vultisig/[email protected]"],"fail_on":"review"}'

GitHub Actions step:

- name: PkgRadar gate
  run: |
    curl -fsS https://pkgradar.com/gate/npm \
      -H "Authorization: Bearer ${{ secrets.PKGRADAR_TOKEN }}" \
      -H "Content-Type: application/json" \
      -d '{"specs":["@vultisig/[email protected]"],"fail_on":"review"}'
Publisherrcoderdev
Artifact bytes21,754,494
Previous version2.0.0
Published2026-06-11T11:10:19.410Z
SHA-2566d1c2d8a1ba0f30d7306cbd80b31856fb7e6bca44ef65fc850047bcb7029f597

Why flagged

What the scanner saw

Large Javascript Payload: 2883039 bytes

Not observed: package install, lifecycle script execution, or sandbox execution. PkgRadar only inspects on-disk artifacts.

Availability ledger

available

low
Last checked
lowRisk
0Score
2.1.0Version
Status history (1 event)
  1. newavailable · risk low · score 0 · status changed

Evidence

Static findings

5 static · 0 from release diff · showing high-signal first.

No high-signal findings — see all findings below.

Show all 5 findings (low-signal and informational)
SeverityKindPathDetailPoints
lowLarge Javascript Payloadpackage/dist/index.browser.js2883039 bytes0
lowLarge Javascript Payloadpackage/dist/index.chrome-extension.js2879324 bytes0
lowLarge Javascript Payloadpackage/dist/index.electron-main.cjs3250209 bytes0
lowLarge Javascript Payloadpackage/dist/index.node.cjs3249868 bytes0
lowLarge Javascript Payloadpackage/dist/index.node.esm.js3238515 bytes0

Manifest

Package metadata

Scripts51
  • _____BUILD_____
  • _____HOOKS_____
  • _____PLATFORM_BUILDS_____
  • _____QUALITY_____
  • _____TEST_BY_TYPE_____
  • _____TEST_E2E_INDIVIDUAL_____
  • _____TEST_RUN_____
  • _____TEST_UTILS_____
  • _____TEST_WATCH_____
  • buildyarn clean && yarn build:platforms && yarn build:types
  • build:fastyarn clean && BUILD_TARGET=node rollup -c rollup.platforms.config.js
  • build:jsyarn build:platforms
  • build:platform:browserBUILD_TARGET=browser rollup -c rollup.platforms.config.js
  • build:platform:chrome-extensionBUILD_TARGET=chrome-extension rollup -c rollup.platforms.config.js
  • build:platform:electronBUILD_TARGET=electron rollup -c rollup.platforms.config.js
  • build:platform:nodeBUILD_TARGET=node rollup -c rollup.platforms.config.js
  • build:platform:react-nativeBUILD_TARGET=react-native rollup -c rollup.platforms.config.js
  • build:platform:viteBUILD_TARGET=vite rollup -c rollup.platforms.config.js
  • build:platformsconcurrently "yarn build:platform:node" "yarn build:platform:browser" "yarn build:platform:electron" "yarn build:platform:chrome-extension" "yarn build:platform:react-native" "yarn build:platform:vite"
  • build:typesrollup -c rollup.types.config.js
  • cleanrm -rf dist
  • devBUILD_TARGET=node rollup -c rollup.platforms.config.js -w
  • linteslint --config ../../.config/eslint.config.mjs src/**/*.{ts,tsx}
  • lint:fixeslint --config ../../.config/eslint.config.mjs src/**/*.{ts,tsx} --fix
  • prepackecho 'Build skipped for development'
  • prepublishOnlyecho 'Typecheck skipped - CI runs quality checks before publish'
  • testvitest run --config tests/unit/vitest.config.ts tests/unit
  • test:allyarn test:unit && yarn test:integration && yarn test:e2e
  • test:changedvitest related --run
  • test:coveragevitest run --config tests/unit/vitest.config.ts tests/unit --coverage
  • …and 21 more.
Dependencies52
  • 7z-wasm^1.2.0
  • @bufbuild/protobuf^2.12.0
  • @coral-xyz/anchor^0.32.1
  • @cosmjs/stargate^0.39.0
  • @formatjs/intl-getcanonicallocales^2.5.0
  • @formatjs/intl-locale^4.2.0
  • @formatjs/intl-numberformat^8.15.0
  • @formatjs/intl-pluralrules^6.3.10
  • @lifi/sdk^3.15.5
  • @mysten/sui^2.17.0
  • @noble/hashes^1.8.0
  • @polkadot/api^16.5.6
  • @scure/bip39^1.6.0
  • @solana/spl-token^0.4.14
  • @solana/web3.js^1.98.4
  • @ton/core^0.63.1
  • @ton/crypto^3.3.0
  • @trustwallet/wallet-core^4.6.13
  • @vultisig/lib-dkls0.9.0
  • @vultisig/lib-mldsa0.9.0
  • @vultisig/lib-schnorr0.9.0
  • @vultisig/mpc-types0.2.3
  • axios^1.17.0
  • bip32^5.0.1
  • bitcoinjs-lib^7.0.1
  • bs58^6.0.0
  • bs58check^4.0.0
  • buffer^6.0.3
  • cbor-x^1.6.4
  • crypto-browserify^3.12.1
  • …and 22 more.