← Home

@botfabrik/engine-webclient

Webclient for Botfabriks Bot Engine

50
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

linus-hueslerphischerromixchpatrik.stutzvespertinuskjenosbenedikt_apptivaalondra-prado

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/assets/index-CxHubEDR.js AI (source-diff): Vite-bundled frontend asset; long lines are minified build output, not obfuscation. ai
source-diff net-exec-file:dist/client/assets/index-CxHubEDR.js AI (source-diff): Browser webclient bundle; fetch + dynamic module loading is expected behavior for this package. ai
source-diff net-exec-file:dist/client/assets/index-DauCjPQ8.js AI (source-diff): Browser fetch + dynamic module loading in a webclient bundle is normal; no hostile destination or dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/index-DauCjPQ8.js AI (source-diff): Standard Vite/esbuild minified bundle output; not true obfuscation. Expected artifact for a webclient package. ai
source-diff net-exec-file:dist/client/assets/index-Dwmr7EiL.js AI (source-diff): Network+exec pattern is standard browser bundle behavior (fetch for modulepreload); no hostile destination. ai
source-diff obfuscated-file:dist/client/assets/index-Dwmr7EiL.js AI (source-diff): Minified Vite/esbuild browser bundle; no true obfuscation signatures present. ai
source-diff obfuscated-file:dist/client/assets/index-TmZ0K7Wr.js AI (source-diff): Standard Vite/esbuild frontend bundle with source map; minified build output, not obfuscation. ai
source-diff net-exec-file:dist/client/assets/index-TmZ0K7Wr.js AI (source-diff): Network calls and dynamic patterns are normal in a bundled webclient SPA; no hostile destination or dropper behavior. ai
source-diff net-exec-file:dist/client/assets/index-B23oVAYe.js AI (source-diff): Network calls are browser fetch for modulepreload; no dropper/loader behavior in the sample. ai
source-diff obfuscated-file:dist/client/assets/index-B23oVAYe.js AI (source-diff): Standard Vite/esbuild minified bundle output; no true obfuscation signatures present. ai
source-diff obfuscated-file:dist/client/assets/index-DR0rhLK_.js AI (source-diff): Standard Vite-bundled React client asset; minified but not obfuscated. Stable pattern for this package. ai
source-diff net-exec-file:dist/client/assets/index-DR0rhLK_.js AI (source-diff): Network calls and dynamic code in a browser bundle are normal React/Vite output; no dropper behavior present. ai
source-diff obfuscated-file:dist/client/assets/index-BFYEgcht.js AI (source-diff): Vite-bundled React frontend output; minification is expected for this webclient package. ai
source-diff net-exec-file:dist/client/assets/index-BFYEgcht.js AI (source-diff): Network calls and dynamic execution are normal browser-side React app behavior; no exfil or dropper pattern present. ai
source-diff obfuscated-file:dist/client/assets/index-qmz848Sp.js AI (source-diff): Standard Vite-bundled React client asset; long lines are minified build output, not obfuscation. ai
source-diff net-exec-file:dist/client/assets/index-qmz848Sp.js AI (source-diff): Network calls are browser fetch() for modulepreload; dynamic execution is React scheduler — normal bundled client code. ai
source-diff obfuscated-file:dist/client/assets/index-Dgye-P8u.js AI (source-diff): Vite-bundled client asset; long lines are minified build output, not obfuscation. Stable pattern for this webclient package. ai
source-diff net-exec-file:dist/client/assets/index-Dgye-P8u.js AI (source-diff): Network calls (fetch) in a browser webclient bundle are expected; no dropper behavior present. ai
source-diff net-exec-file:dist/client/assets/index-iPU9jlP1.js AI (source-diff): Network calls and dynamic patterns are standard React/Vite bundle behavior, not dropper malware. ai
source-diff obfuscated-file:dist/client/assets/index-iPU9jlP1.js AI (source-diff): Vite-bundled React client asset; minified build output, not obfuscation. ai
publish-pattern rapid-publish AI (publish-pattern): Package has 582 versions with frequent releases; rapid publish is consistent with automated CI pipeline, not malicious activity. ai
source-diff net-exec-file:dist/client/assets/index-BhKwcsbz.js AI (source-diff): Network calls are browser fetch() for modulepreload in a webclient UI bundle; no hostile destination or dynamic code execution. ai
source-diff obfuscated-file:dist/client/assets/index-BhKwcsbz.js AI (source-diff): Standard Vite/esbuild minified bundle output; no true obfuscation (_0x arrays, eval/atob, packer) present. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): uuid is explicitly declared in package.json dependencies; phantom-dep heuristic fires incorrectly here. ai
source-diff net-exec-file:dist/client/assets/index-kLumE_Is.js AI (source-diff): Network calls (fetch for modulepreload) and dynamic module loading are standard in bundled SPA code; not dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/index-kLumE_Is.js AI (source-diff): Vite-bundled frontend asset; minification is expected for this webclient package across all versions. ai
dependencies unvetted-dep:@botfabrik/engine-domain AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. ai
dependencies unvetted-dep:@botfabrik/engine-transcript-export AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. ai
dependencies unvetted-dep:@botfabrik/engine-utils AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. ai
phantom-deps phantom-dep:@types/cors AI (phantom-deps): @types/cors is a TypeScript type package; not imported at runtime by convention. ai
provenance no-provenance AI (provenance): Long-established package with 535 versions; lack of provenance is consistent across all prior releases. ai

Versions (showing 50 of 50)

Version Deps Published
4.132.2 13 / 8
4.126.2 13 / 8
4.123.7 13 / 8
4.122.1 13 / 8
4.120.2 13 / 8
4.117.2 13 / 8
4.116.11 13 / 8
4.116.10 13 / 8
4.116.8 13 / 8
4.116.7 13 / 8
4.116.5 13 / 8
4.116.4 13 / 8
4.116.3 13 / 8
4.116.2 13 / 8
4.116.1 13 / 8
4.116.0 13 / 8
4.115.18 13 / 8
4.115.16 13 / 8
4.115.15 13 / 8
4.115.11 13 / 8
4.115.9 13 / 8
4.115.8 13 / 8
4.115.7 13 / 8
4.115.5 13 / 8
4.113.1 13 / 8
4.110.4 13 / 8
4.110.2 13 / 8
4.108.1 9 / 7
4.108.0 9 / 7
4.106.0 9 / 7
4.105.0 9 / 7
4.104.23 9 / 7
4.104.19 9 / 7
4.104.3 10 / 8
4.103.3 10 / 8
4.102.0 10 / 10
4.101.2 10 / 10
4.101.0 10 / 10
4.100.9 10 / 10
4.99.10 10 / 10
4.99.0 11 / 10
4.96.9 7 / 9
4.96.6 7 / 9
4.96.1 7 / 9
4.94.1 7 / 9
4.93.0 8 / 10
4.92.2 8 / 10
4.89.0 7 / 9
4.86.3 9 / 8
4.86.1 9 / 8

v4.120.2

3 findings
HIGH New obfuscated file: dist/client/assets/index-Dwmr7EiL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-Dwmr7EiL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.116.4

3 findings
HIGH New obfuscated file: dist/client/assets/index-Dgye-P8u.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-Dgye-P8u.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.115.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.113.1

3 findings
HIGH New obfuscated file: dist/client/assets/index-TmZ0K7Wr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-TmZ0K7Wr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.110.4

3 findings
HIGH New obfuscated file: dist/client/assets/index-iPU9jlP1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-iPU9jlP1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.110.2

3 findings
HIGH New obfuscated file: dist/client/assets/index-DR0rhLK_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-DR0rhLK_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.108.1

3 findings
HIGH New obfuscated file: dist/client/assets/index-BFYEgcht.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-BFYEgcht.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.108.0

3 findings
HIGH New obfuscated file: dist/client/assets/index-BFYEgcht.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-BFYEgcht.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.104.3

3 findings
HIGH New obfuscated file: dist/client/assets/index-qmz848Sp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/index-qmz848Sp.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.