@antv/vendor@1.0.11
Vendored dependencies to fix ERR_REQUIRE_ESM.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
// publisher campaign · npm
All caught packages published by the bqxbqxbqx account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.
Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.
An email from this campaign also appears on caught packages under a different publisher account. Strong evidence that one operator runs both handles.
Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.
Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.
Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.0/8 caught.
npm package name robbery.
npm package name robbery.






Vendored dependencies to fix ERR_REQUIRE_ESM.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).