Attaint Deployed on Bradbury

The version number is not the change.

Attaint judges the pinned diff of a release and answers one question: does this update carry a risk the version number does not report?

A patch release that adds a dependency, hands the package to a new publisher, or ships an install script is in no vulnerability database. That is what every headline supply-chain attack looked like on the day it landed.

Illustrative examples · no chain verdicts
Illustration · package.json
"dependencies": {
}

RISK exit 1

Bradbury · live consensus

One update. One pinned policy. A chain verdict.

The published attestation loads directly from Bradbury without a wallet. Expand its receipt to check finality. To judge another update, build its envelope locally and submit it with your Bradbury wallet.

Contract: Awaiting verified deployment

No policy loaded.

Submit an update

New requests need testnet GEN. Acceptance usually precedes finality by about 30 minutes. Keep the hash and resume the same request while it is pending.

Or paste an envelope

No envelope selected.

Inspect the evidence before signing

Create your envelope: python3 cli/envelope.py PACKAGE FROM TO --out update.json. Checksums verify downloaded bytes. The contract checks registry metadata; file excerpts rely on this builder. A CLEAN result covers the supplied evidence and policy.

Read the chain gate

No chain result loaded
Gate record
Consensus receipt

Reading deployment manifest…

2 October checkpoint: 22/45 finalized gates (14 clean, 8 inconclusive). Two additional finalized receipts await current-state verification. The separate benchmark contract exceeds the public node’s history-read capacity; the full comparison remains pending. The live app uses a separate instance with the same code and policy. Readback audit.

GitHub repository · Contract source · Evidence builder · CLI gate · Complete source archive · 45-pair baseline · Consensus report

Evidence has a level, and the level bounds what can be said

Every headline npm incident has had its malicious versions unpublished. The tarballs return 404 and the version manifests are gone. What survives is the checksum recorded in other people's lockfiles, together with the resolved dependency graph.

Level 1 — registry pin

Bytes in hand

Both tarballs downloaded and hashed against the integrity the registry published. Registry metadata can be checked. File-based classes require complete bounded excerpts; missing coverage stays inconclusive.

Level 2 — lockfile rebuild

Checksum without the file

The tarball is gone. The checksum and the dependency graph are recovered from independent lockfiles. Publisher changes and added dependencies are still judged; anything needing file contents returns inconclusive.

Level 3 — nothing

Inconclusive, always

No pin, no verdict. This blocks rather than passes, because making the evidence unreadable is otherwise the cheapest attack there is.

A clean verdict that does not say which level produced it is a lie about what was checked. The level is written into the attestation and returned by the gate.

A detector that fires on three updates in five gets switched off

Forty-five consecutive releases of fifteen ordinary packages, read the way a deterministic linter reads them. This is the number a supply-chain gate lives or dies on, and it is rarely published.

Ordinary releases blocked

The obfuscated-blob rule alone fires on nearly half the sample, because a minified dist directory is ordinary npm practice. It flags esbuild, prettier, axios and glob in a row. Adding a second maintainer is routine housekeeping, not a handover.

So the classes are not written as detections. Attaint does not ask whether an install script appeared; it asks whether the script does something the build of this package does not need. That question has no regular expression, which is the entire reason it goes to consensus instead of a linter.

Measured 4 September 2026 against the live npm registry. The prefilter that produces a candidate never decides anything — it extracts and pins, and the verdict is the validators'.

What is left of the famous incidents

Seven of nine evidence pairs cannot be pinned from the registry any more. The checksums were recovered from third-party lockfiles instead, and recovery turns out to be inversely proportional to how fast the incident was caught.

VersionPinIndependent repositoriesWhat it shows

event-stream 3.3.6 sat in the registry for about ten weeks and settled into thirty lockfiles. The ua-parser-js versions were pulled within hours and left almost no trace. The rows that recovered nothing stay on this page rather than being quietly dropped.

The bytes are not recoverable at all: npm and the yarn mirror both return 404, and GitHub excludes node_modules from its code search index. A recovered checksum is a number that would verify an archived copy, not a copy.

The evidence is written by whoever is being judged

A release description, a README, the text of an install script — all of it is authored by the publisher under review. That is injection into fetched content, and a single model is defeated by trying wordings until one lands.

Attaint uses a quoting fence derived from the hash of the evidence, so the evidence cannot close it early. Judges read the pinned evidence as supplied; duplicate requests are scoped to the release, checksum pins, policy and requester. A round that cannot be parsed is inconclusive and blocks the gate.

A challenger who thinks a class was missed stakes a bond and points at a fragment. Before any consensus round is spent, the contract checks the fragment appears verbatim in the pinned evidence. Producing a different commit, a different version, or a later release is not a finding — it is a different object, and the bond is forfeit. Without that check the bonded market simply pays for swapping the facts.

Illustrative evidence — no on-chain challenge

      
Stake a bond, point at a fragment

Where this sits

Not a vulnerability scanner

Those compare versions against a database of what is already known. A patch release carrying exfiltration appears in no database on the day it ships.

Not a vendor verdict

Behavioural supply-chain tools judge the same object and reach it first. The difference is not the subject, it is the trust model: their verdict cannot be contested, is validated by a private research team, and cannot be recomputed by anyone else. Here the verdict is bonded, replayable against pinned evidence, and the consumer policy is fixed on chain so the gate cannot be quietly relaxed.

Not Jastrow, not Suborn

Jastrow asks whether a specification is decidable at all. Suborn asks whether a decidable specification survives hostile evidence. Attaint applies that defence to one object — a package update — and adds the consumer's policy.