// npm package
@antv/li-sam-assets
Standard Tooling for location insight assets
versions
4
maintainers
51
license
MIT
first publish
2023-07-06
publisher
yanxiong
tarball
79,308,199 B
AUTO-PUBLISHED·2 versions indexed·latest published 2023-07-10
// publisher campaignby yanxiong
6 caught packages from this accountThis is not an isolated catch. The same publisher has shipped 5 other packages that our pipeline flagged — the shape of a coordinated campaign, not a one-off. Each link below opens that sibling's analysis.
// offending code· @0.1.4· no static-pattern hits
llm: benign · 0.85→ No suspicious destination, no remote-exec shape — no network destinations.
- @0.1.4··AUTO-PUBLISHED·publisher: yanxiongheuristic 75/100static flags 1llm benign (0.85) via ollamahuge-tarball:76mbosv-flagged:MAL-2026-4064oversize-tarball-skipped
→ No suspicious destination, no remote-exec shape — no network destinations.
// offending code· no static-pattern hitspatterns: 1
(tarball 21391835 bytes > 20971520 cap; static analysis skipped)
- @0.1.3··AUTO-PUBLISHED·publisher: yanxiongheuristic 75/100static flags
