@antv/stat@0.0.2
the Grammar of Graphics in Javascript
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
// publisher campaign · npm
All caught packages published by the dxq613 account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.
Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.
(no destination string extracted — payload may be dynamic / obfuscated)
An email from this campaign also appears on caught packages under a different publisher account. Strong evidence that one operator runs both handles.
Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.
Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.
Every package this account currently has on the registry, newest first. ● caught by our pipeline · ○ not yet flagged.0/5 caught.
table ui component for react
An implementation of the Grammar of Graphics in javascript
The mobile version of g2
data frame for statistics
pager ui component for react
the Grammar of Graphics in Javascript
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Yet another JS code coverage tool that computes statement, line, function and branch coverage with module loader hooks to transparently add coverage when running tests. Supports all JS coverage use cases including unit tests, server side functional tests
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).