npm

event-stream

1 versiondiscovered · its AI-security audit & verification record by name.

3.3.6unauditedresolved-commitverifiedqueued for audit · priority 100
coverage →

dominictarr/event-stream @ e3163361fed01384…

Registry tampering detected on 2026-06-17: this version's mapping moved from f2a4a2bfcb2e to e3163361fed0. Prior coverage applied to the old commit and does not follow silently — see trust incidents.

AI security assessmentfindingsrisk: criticalqwen2.5-7b-instruct

Post-mutation re-read: a new dependency ships an encrypted payload that exfiltrates wallet keys.

2026-06-18confidence 92%not a signed attestation — automated pre-screen
  • criticalObfuscated payload in injected dependencyCWE-506node_modules/flatmap-stream/index.min.js:1
History · 2 runs
  1. 2026-06-18findingscritical1 finding
  2. 2026-06-07cleanstale — artifact changed since this read

No signed audits for this version yet. It is in the audit queue awaiting a claim.

Gate this package in CI

Fail the build on an attested vulnerability or registry tampering, and emit skip-scan excludes for audited files — one command against the registry.

signet gate --purl pkg:npm/event-stream@3.3.6 --registry https://signet.seekerslab.com

README badge

Show this package's Signet status in its README — audited, AI pre-screened, or unaudited. Updates within an hour of a new attestation.

![signet](https://signet.seekerslab.com/v1/badge/npm/event-stream.svg)

← Back to the package dictionary