@metamask/test-dapp-multichain
A test dapp for multichain api
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:build/static/js/main.5ae66812.js | AI (source-diff): Bundled app code, network+eval patterns are standard library code, not a dropper. | ai | |
| source-diff | obfuscated-file:build/static/js/main.5ae66812.js | AI (source-diff): CRA/webpack minified bundle, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/599.c7a86e62.chunk.js | AI (source-diff): Webpack chunk bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/878.4fa64963.chunk.js | AI (source-diff): Webpack chunk bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/main.85a9889b.js | AI (source-diff): CRA main bundle, minified build output. | ai | |
| source-diff | net-exec-file:build/static/js/main.85a9889b.js | AI (source-diff): Bundled crypto/network libs in CRA build, no malicious behavior found. | ai | |
| source-diff | net-exec-file:build/static/js/main.ce0d44fe.js | AI (source-diff): Bundled web app code with fetch + dynamic exec patterns inherent to webpack runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:build/static/js/main.ce0d44fe.js | AI (source-diff): CRA/webpack minified bundle, not true obfuscation; standard build artifact for this dapp. | ai | |
| source-diff | obfuscated-file:build/static/js/879.c03d62c0.chunk.js | AI (source-diff): Webpack chunk bundling QR-code lib, standard minified output. | ai | |
| source-diff | obfuscated-file:build/static/js/878.7a64e09c.chunk.js | AI (source-diff): Webpack chunk, standard minified UI/runtime code. | ai | |
| source-diff | obfuscated-file:build/static/js/599.6669e12c.chunk.js | AI (source-diff): Webpack chunk, standard minified UI component code. | ai | |
| source-diff | net-exec-file:build/static/js/main.41d0f32b.js | AI (source-diff): False positive: bundled crypto/utility libs, no actual network+exec dropper behavior. | ai | |
| source-diff | obfuscated-file:build/static/js/main.41d0f32b.js | AI (source-diff): Webpack bundle of CRA app incl. crypto/JSON-pointer libs, not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/static/js/main.8a3c63f7.js | AI (source-diff): Bundled dapp code with fetch/eval polyfills, not a dropper; expected for CRA build. | ai | |
| source-diff | obfuscated-file:build/static/js/main.8a3c63f7.js | AI (source-diff): CRA/webpack bundle output, not true obfuscation; matches build script. | ai | |
| source-diff | obfuscated-file:build/static/js/main.81eb0117.js | AI (source-diff): CRA/webpack bundle minification, not true obfuscation; recurring on this build-artifact package. | ai | |
| source-diff | net-exec-file:build/static/js/main.81eb0117.js | AI (source-diff): Bundled React dapp with fetch + dynamic code paths is expected, not a dropper. | ai | |
| source-diff | obfuscated-file:build/static/js/main.4426a5f6.js | AI (source-diff): CRA/webpack production bundle; minified, not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/static/js/main.4426a5f6.js | AI (source-diff): Standard webpack chunk-loading + fetch in bundled CRA output. | ai | |
| source-diff | obfuscated-file:build/static/js/main.616a56e8.js | AI (source-diff): CRA/webpack bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/main.616a56e8.js | AI (source-diff): Bundled CRA app; network+eval patterns are standard bundler/polyfill code. | ai | |
| source-diff | obfuscated-file:build/static/js/main.fd07ddaa.js | AI (source-diff): CRA/webpack minified bundle, not obfuscation; standard build output for this test dapp. | ai | |
| source-diff | net-exec-file:build/static/js/main.fd07ddaa.js | AI (source-diff): Bundled React app naturally contains fetch + eval-like polyfills; no malicious behavior found. | ai | |
| phantom-deps | phantom-dep:@metamask/utils | AI (phantom-deps): Same-org dependency; likely loaded via transitive deps or config. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): CRA convention; react loaded implicitly by react-scripts and JSX. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): CRA convention; react-dom loaded implicitly by react-scripts. | ai | |
| phantom-deps | phantom-dep:react-scripts | AI (phantom-deps): CRA build tool; loaded via npm scripts, not direct import. | ai | |
| phantom-deps | phantom-dep:@testing-library/react | AI (phantom-deps): Testing framework loaded by convention in CRA test setup. | ai | |
| phantom-deps | phantom-dep:@testing-library/jest-dom | AI (phantom-deps): Jest setup file convention; loaded implicitly. | ai | |
| phantom-deps | phantom-dep:@types/chrome | AI (phantom-deps): TypeScript types loaded by convention for browser APIs. | ai | |
| phantom-deps | phantom-dep:@metamask/api-specs | AI (phantom-deps): Same-org dependency; likely loaded via transitive deps or config. | ai | |
| phantom-deps | phantom-dep:@open-rpc/meta-schema | AI (phantom-deps): Schema package loaded via config or transitive deps. | ai | |
| phantom-deps | phantom-dep:@open-rpc/schema-utils-js | AI (phantom-deps): Schema utility loaded via config or transitive deps. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Gap consistent with test-dapp release cadence, no other risk signal. | ai | |
| source-diff | net-exec-file:build/static/js/main.dd85a362.js | AI (source-diff): Bundled crypto/util libs in build output, no dropper behavior observed. | ai | |
| source-diff | obfuscated-file:build/static/js/main.dd85a362.js | AI (source-diff): CRA/webpack production bundle; minified, not obfuscated malware. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Normal team roster changes for long-running MetaMask repo. | ai | |
| source-diff | obfuscated-file:build/static/js/main.d6a21d16.js | AI (source-diff): React/CRA build output; minified webpack bundle is expected for this test-dapp package. | ai | |
| source-diff | net-exec-file:build/static/js/main.d6a21d16.js | AI (source-diff): Network calls and dynamic execution are inherent to a browser dapp bundle; not dropper behavior. | ai | |
| source-diff | net-exec-file:build/static/js/main.7e480294.js | AI (source-diff): Network+eval pattern in a React dapp bundle is expected; not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/static/js/main.7e480294.js | AI (source-diff): Standard CRA/webpack minified bundle; this package always ships a React build artifact. | ai | |
| source-diff | obfuscated-file:build/static/js/main.e323f87a.js | AI (source-diff): Standard CRA/webpack minified bundle; this package ships a React build as its artifact. | ai | |
| source-diff | net-exec-file:build/static/js/main.e323f87a.js | AI (source-diff): Network calls and dynamic code in a React test dapp bundle are expected; no malware indicators in sample. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Test dapp with build artifact; README link dump and no keywords are expected for this package type. | ai | |
| source-diff | net-exec-file:build/static/js/main.96d18c46.js | AI (source-diff): Network+eval pattern is from bundled React app code, not dropper malware. | ai | |
| source-diff | obfuscated-file:build/static/js/main.96d18c46.js | AI (source-diff): Standard CRA/webpack minified bundle; this package always ships a built React app. | ai | |
| source-diff | obfuscated-file:build/static/js/main.6a460b87.js | AI (source-diff): Standard webpack/React minified build bundle; this package always ships a compiled build/ directory. | ai | |
| source-diff | net-exec-file:build/static/js/main.6a460b87.js | AI (source-diff): Network calls and dynamic execution are expected in a React dapp bundle; not dropper behavior. | ai | |
| source-diff | net-exec-file:build/static/js/main.a5690022.js | AI (source-diff): Network calls + dynamic execution are inherent to a wallet test dapp bundle; not malware indicators here. | ai | |
| source-diff | obfuscated-file:build/static/js/main.a5690022.js | AI (source-diff): Standard CRA minified bundle; source map included. Expected for this React dapp package. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 0.19.1 | 0 / 35 | |
| 0.19.0 | 0 / 35 | |
| 0.18.1 | 0 / 35 | |
| 0.18.0 | 0 / 35 | |
| 0.17.1 | 0 / 38 | |
| 0.17.0 | 0 / 38 | |
| 0.16.0 | 0 / 38 | |
| 0.15.0 | 0 / 38 | |
| 0.14.0 | 0 / 38 | |
| 0.13.0 | 0 / 38 | |
| 0.12.1 | 0 / 38 | |
| 0.12.0 | 0 / 38 | |
| 0.11.0 | 0 / 38 | |
| 0.10.0 | 0 / 38 | |
| 0.9.0 | 0 / 38 | |
| 0.8.0 | 0 / 38 | |
| 0.7.0 | 0 / 36 | |
| 0.6.0 | 0 / 36 | |
| 0.5.0 | 0 / 36 | |
| 0.4.1 | 0 / 36 | |
| 0.4.0 | 10 / 26 | |
| 0.3.2 | 10 / 26 | |
| 0.3.1 | 10 / 26 |
v0.19.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.