@metamask/browser-playground
A browser test dapp for multichain api
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/static/js/main.6a2d097e.js | AI (source-diff): Webpack build output for this CRA dapp; recurs every release. | ai | |
| source-diff | net-exec-file:build/static/js/main.6a2d097e.js | AI (source-diff): Minified webpack bundle with normal fetch+dynamic import; no hostile target. | ai | |
| source-diff | net-exec-file:build/static/js/main.9ff152f2.js | AI (source-diff): Bundled dapp main.js; network+eval are normal in webpack runtime, no hostile target. | ai | |
| source-diff | obfuscated-file:build/static/js/main.9ff152f2.js | AI (source-diff): Webpack CRA build output for official MetaMask dapp; minified not obfuscated. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query-persist-client | AI (phantom-deps): React app; query persistence referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@metamask/chain-agnostic-permission | AI (phantom-deps): Same-org dependency; referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): React app; query library referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@metamask/connect | AI (phantom-deps): Same-org dependency; referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@metamask/utils | AI (phantom-deps): Same-org dependency; referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:@wagmi/core | AI (phantom-deps): Web3 playground; wagmi core referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): React app; dependencies used via build tooling and config, not direct imports. | ai | |
| phantom-deps | phantom-dep:wagmi | AI (phantom-deps): Web3 playground; wagmi referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:viem | AI (phantom-deps): Web3 playground; viem referenced in config/build, not direct imports. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): React app; dependencies used via build tooling and config, not direct imports. | ai | |
| phantom-deps | phantom-dep:@tanstack/query-sync-storage-persister | AI (phantom-deps): React app; storage persister referenced in config/build, not direct imports. | ai | |
| source-diff | net-exec-file:build/static/js/main.e57553a4.js | AI (source-diff): Bundled browser dapp; fetch+eval patterns are normal web app build output, no hostile target. | ai | |
| source-diff | obfuscated-file:build/static/js/main.e57553a4.js | AI (source-diff): Webpack main bundle; minified build output. | ai | |
| source-diff | obfuscated-file:build/static/js/817.bf92ca72.chunk.js | AI (source-diff): Webpack chunk build output; minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/static/js/main.453599dc.js | AI (source-diff): Standard SPA bundle fetch + dynamic import; no hostile destination. | ai | |
| source-diff | obfuscated-file:build/static/js/main.453599dc.js | AI (source-diff): Webpack main bundle build output; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:build/static/js/29.1c56f7d4.chunk.js | AI (source-diff): Webpack chunk build output for MetaMask dapp; minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/static/js/main.871af264.js | AI (source-diff): Bundled React dapp; net+exec are normal web3 client code, no hostile target. | ai | |
| source-diff | obfuscated-file:build/static/js/main.871af264.js | AI (source-diff): Webpack/craco minified build output with license banner; not obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/main.91bcc648.js | AI (source-diff): Bundled web-app code; network+exec are normal browser dapp bundle content, no hostile target. | ai | |
| source-diff | obfuscated-file:build/static/js/main.91bcc648.js | AI (source-diff): Webpack-minified CRA build output for this dapp; not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): Migration from metamaskbot to GitHub Actions with SLSA provenance; legitimate CI change. | ai | |
| source-diff | obfuscated-file:build/static/js/main.6a70c790.js | AI (source-diff): Standard webpack production bundle for a React app; expected for this package. | ai | |
| source-diff | net-exec-file:build/static/js/main.6a70c790.js | AI (source-diff): Bundled dapp code with network calls and eval from webpack runtime; not malicious. | ai | |
| source-diff | net-exec-file:build/static/js/main.1ec9cd95.js | AI (source-diff): Bundled React app with fetch calls and eval from webpack runtime; not malicious. | ai | |
| source-diff | obfuscated-file:build/static/js/main.1ec9cd95.js | AI (source-diff): Standard CRA webpack production bundle; expected for this browser playground package. | ai | |
| source-diff | net-exec-file:build/static/js/main.ddd1d44e.js | AI (source-diff): Bundled React app naturally contains fetch/eval patterns; not malicious for this package. | ai | |
| source-diff | obfuscated-file:build/static/js/main.ddd1d44e.js | AI (source-diff): Standard CRA/webpack production bundle; minification expected for this browser playground package. | ai | |
| source-diff | obfuscated-file:build/static/js/main.5a1e472c.js | AI (source-diff): Standard webpack minified build output for a MetaMask browser playground; expected artifact. | ai | |
| source-diff | net-exec-file:build/static/js/main.5a1e472c.js | AI (source-diff): Network calls and dynamic module loading are inherent to a bundled React dapp; no dropper/loader pattern present. | ai | |
| source-diff | net-exec-file:build/static/js/main.31e1a1d6.js | AI (source-diff): Browser app bundle combining fetch/XHR with dynamic module loading is expected for a React dapp; no dropper pattern evident in samples. | ai | |
| source-diff | obfuscated-file:build/static/js/main.31e1a1d6.js | AI (source-diff): Standard webpack-minified React app bundle; source maps included; legitimate MetaMask playground package. | ai | |
| source-diff | net-exec-file:build/static/js/main.11fdc90f.js | AI (source-diff): Browser dapp bundle legitimately contains fetch calls and dynamic module loading via webpack runtime; not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/static/js/main.11fdc90f.js | AI (source-diff): Standard webpack minified main bundle from craco build; expected output for this browser playground package. | ai | |
| source-diff | obfuscated-file:build/static/js/288.51cc5192.chunk.js | AI (source-diff): Standard webpack-minified React build output for a browser dapp; not obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/main.2f01c3f9.js | AI (source-diff): Browser dapp bundle; network calls and dynamic module loading are expected in a webpack React app. | ai | |
| source-diff | obfuscated-file:build/static/js/main.2f01c3f9.js | AI (source-diff): Standard webpack-minified React build output for a browser dapp; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/921.58d10f34.chunk.js | AI (source-diff): Standard webpack-minified React build output for a browser dapp; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/127.6f28ac63.chunk.js | AI (source-diff): Standard webpack-minified React build output for a browser dapp; not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/main.8cb80a7d.js | AI (source-diff): Standard webpack minified build output for a React dapp; not obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/main.8cb80a7d.js | AI (source-diff): Network calls and dynamic module loading are expected in a bundled browser dapp; no dropper behavior evident. | ai | |
| source-diff | obfuscated-file:build/static/js/29.8d088763.chunk.js | AI (source-diff): Standard webpack minified build output for a React dapp; not obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/main.68735b63.js | AI (source-diff): Network calls and dynamic module loading are normal in a bundled React dapp; no dropper behavior evident in sample. | ai | |
| source-diff | obfuscated-file:build/static/js/main.68735b63.js | AI (source-diff): Standard CRA/craco production bundle; minified output is expected for this browser playground package. | ai | |
| source-diff | net-exec-file:build/static/js/main.4f702492.js | AI (source-diff): React SPA bundle legitimately contains fetch calls and dynamic module loading; no dropper pattern present. | ai | |
| source-diff | obfuscated-file:build/static/js/main.4f702492.js | AI (source-diff): Standard CRA webpack bundle for a browser playground; minification is expected, not malicious. | ai | |
| source-diff | net-exec-file:build/static/js/main.8bf2a014.js | AI (source-diff): Network calls + dynamic module loading are normal in a bundled React dapp; no dropper indicators in sampled code. | ai | |
| source-diff | obfuscated-file:build/static/js/main.8bf2a014.js | AI (source-diff): Standard CRA webpack bundle; minification is expected for this browser playground package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 0.8.1 | 0 / 51 | |
| 0.8.0 | 0 / 51 | |
| 0.7.5 | 0 / 51 | |
| 0.7.4 | 0 / 51 | |
| 0.7.3 | 0 / 51 | |
| 0.7.2 | 0 / 51 | |
| 0.7.1 | 0 / 51 | |
| 0.7.0 | 0 / 51 | |
| 0.6.6 | 0 / 51 | |
| 0.6.5 | 0 / 51 | |
| 0.6.4 | 0 / 51 | |
| 0.6.3 | 0 / 51 | |
| 0.6.2 | 0 / 51 | |
| 0.6.1 | 0 / 51 | |
| 0.6.0 | 0 / 51 | |
| 0.5.1 | 0 / 51 | |
| 0.5.0 | 0 / 51 | |
| 0.4.2 | 0 / 51 | |
| 0.4.1 | 0 / 51 | |
| 0.4.0 | 0 / 51 | |
| 0.3.1 | 0 / 51 | |
| 0.3.0 | 0 / 51 | |
| 0.2.0 | 0 / 51 | |
| 0.1.1 | 11 / 36 | |
| 0.1.0 | 11 / 36 |
v0.5.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.