Platform-specific prebuilt native binary (os: darwin, cpu: arm64). Inspected the 10.1 MB native artifact (bin/esbuild) directly — sha256 e2dc9a52440a…: no malicious indicators in its embedded strings and no tamper vs. prior releases. Not runnable on the scan host by design; expected for a cross-platform binary package.
Prebuilt native binaries
Compiled artifacts fetched at install time — the bytes that actually run.
sha256: e2dc9a52440a2a34f09434a2f4843cb1e30f84e40dcf238976ec61ef8cd7f36aPackage metadata
The macOS ARM 64-bit binary for esbuild, a JavaScript bundler.
Files in package (4)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/%40esbuild/darwin-arm64