Platform-specific prebuilt native binary (os: linux, cpu: ppc64). Inspected the 22.8 MB native artifact (lib/tsc) directly — sha256 2bb35c390ee7…: no malicious indicators in its embedded strings and no tamper vs. prior releases. Not runnable on the scan host by design; expected for a cross-platform binary package.
Prebuilt native binaries
Compiled artifacts fetched at install time — the bytes that actually run.
sha256: 2bb35c390ee7574b388b05b202ae05132e4785c6a8b45a76473d2feec3db5e65Security findings (2)
Static analysis rule matches, with the exact code that triggered them.
Multiple obfuscation patterns in lib/lib.es5.d.ts
Multiple obfuscation patterns in package/lib/lib.es5.d.ts
Package metadata
TypeScript is a language for application scale JavaScript development
Files in package (222)
How ShadowCanopy checks npm packages
ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.
This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/%40typescript/typescript-linux-ppc64