@antv/l7-react@2.4.3
L7-React 已全面 升级为 LarkMap,不在进行维护 。 LarkMap 空间数据可视分析组件库
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
// publisher campaign · npm
All caught packages published by the lviser account on npm, plus the author + maintainer info the registry currently exposes. Use this view to pivot: shared emails / names across packages are strong evidence of a single attacker behind multiple throwaway handles.
Account-level signals. Activity span tells you how long this handle has been around (fresh = throwaway-prone). Email domains separate single-use webmail from real org addresses. Cross-ecosystem handles + GitHub links are the strongest attribution pivot — same name on multiple registries usually means same operator.
Not available on this ecosystem (registry search unsupported).
An email from this campaign also appears on caught packages under a different publisher account. Strong evidence that one operator runs both handles.
Same email or author name on more than one package — direct attribution evidence beyond the shared publisher account.
Static-analysis flags that fired across the campaign, with how many packages each touched. Use as the "what kind of stealer is this" answer.
L7-React 已全面 升级为 LarkMap,不在进行维护 。 LarkMap 空间数据可视分析组件库
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).