@stelnyx/report-theme3 versions·0.1.2→0.1.4
Unified theme + template helpers for Stelnyx CLI reports (LuxScope, LuxFaber, SecGate).
// publisher campaign · npm
All caught packages published by the doceno account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.
Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.
Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.
Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.
Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.3/5 caught.
Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.
Tiny static API surface audit — enumerates HTTP endpoints, classifies auth posture, diffs against OpenAPI specs. Zero network, deterministic, one report.
Unified theme + template helpers for Stelnyx CLI reports (LuxScope, LuxFaber, SecGate).
Deterministic guardrails for TypeScript AI agent loops. Tool-call validation, dollar-cost circuit breakers, loop detection. No LLM dependency.
Local-first memory and assertion ledger for AI coding agents. Confidence-weighted, contradiction-aware, token-budgeted context over MCP.
Unified theme + template helpers for Stelnyx CLI reports (LuxScope, LuxFaber, SecGate).
Tiny static API surface audit — enumerates HTTP endpoints, classifies auth posture, diffs against OpenAPI specs. Zero network, deterministic, one report.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Tiny security gate for CI/CD — orchestrates Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit with a premium HTML report.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).