Top issues
Problem
Crypto tokens are versatile digital assets used within the blockchain ecosystem. Crypto tokens are used to represent a wide range of values, rights, or utilities. They play a crucial role in decentralized finance (DeFi), governance, and other blockchain-based applications. Most crypto tokens are built on existing blockchains using smart contracts. A smart contract is a self-executing contract with the terms of the agreement directly written as lines of code. These contracts automatically execute and enforce themselves when predetermined conditions are met, without the need for intermediaries. For this reason, attackers often aim to steal crypto tokens from the machines they infect. Once stolen, crypto tokens are difficult to trace or recover due to the decentralized and pseudonymous nature of blockchain technology. The irreversibility of blockchain transactions means that once the tokens are transferred to the another crypto wallet, they are effectively gone, making them an attractive target for financially motivated actors. While presence of regex code that detects crypto tokens does not imply malicious intent, all of its uses in a software package should be documented and approved. Only select applications should consider working with crypto tokens.Prevalence in npm community
0 packages
found in
Top 100
0 packages
found in
Top 1k
4 packages
found in
Top 10k
2976 packages
in community
Next steps
Investigate reported detections as indicators of software tampering.
Consider rewriting the flagged code without using the marked behaviors.
Problem
Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. A port number is associated with a network address of a host, such as an IP address, and the type of network protocol used for communication. Within URLs, the ports are optional. Ports can be specified in a URL immediately following the domain name. Each network protocol, or schema, has a set of standard ports on which the service operates. This issue is raised when a mismatch between a network protocol and its expected port number is detected. While the presence of non-standard ports does not imply malicious intent, all of their uses in a software package should be documented and approved.Prevalence in npm community
6 packages
found in
Top 100
41 packages
found in
Top 1k
869 packages
found in
Top 10k
490844 packages
in community
Next steps
Investigate reported detections.
If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
You should delay the software release until the investigation is completed, or until the issue is risk accepted.
Consider changing the port to one that is standard for the networking protocol.
Top behaviors
Contains URLs that link to interesting file formats.
network
Prevalence in npm community
Behavior often found in this community (Common)
5 packages
found in
Top 100
39 packages
found in
Top 1k
518 packages
found in
Top 10k
107169 packages
in community
Contains URLs that use non-standard ports.
network
Prevalence in npm community
Behavior often found in this community (Common)
6 packages
found in
Top 100
41 packages
found in
Top 1k
869 packages
found in
Top 10k
491126 packages
in community
Might evaluate code dynamically.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
22 packages
found in
Top 100
120 packages
found in
Top 1k
1482 packages
found in
Top 10k
342917 packages
in community
Contains unusually long strings.
anomaly
Prevalence in npm community
Behavior often found in this community (Common)
0 packages
found in
Top 100
0 packages
found in
Top 1k
25 packages
found in
Top 10k
4626 packages
in community
Might use the Credential Management API.
steal
Prevalence in npm community
Behavior often found in this community (Common)
0 packages
found in
Top 100
1 packages
found in
Top 1k
133 packages
found in
Top 10k
51439 packages
in community
Top vulnerabilities
No vulnerabilities found.