
Research
Malicious npm Packages Impersonate Flashbots SDKs, Targeting Ethereum Wallet Credentials
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
@adrianmaj/typebot-js
Advanced tools
Frontend library to embed typebots from Typebot.
To install, simply run:
npm install @typebot.io/js
<script type="module">
import Typebot from 'https://cdn.jsdelivr.net/npm/@typebot.io/js@0/dist/web.js'
Typebot.initStandard({
typebot: 'my-typebot',
})
</script>
<typebot-standard style="width: 100%; height: 600px; "></typebot-standard>
You can get the standard HTML and Javascript code by clicking on the "HTML & Javascript" button in the "Share" tab of your typebot.
There, you can change the container dimensions. Here is a code example:
<script type="module">
import Typebot from "https://cdn.jsdelivr.net/npm/@typebot.io/js@0/dist/web.js";
Typebot.initStandard({
typebot: "my-typebot",
});
</script>
<typebot-standard style="width: 100%; height: 600px; "></typebot-standard>
This code is creating a container with a 100% width (will match parent width) and 600px height.
You can get the popup HTML and Javascript code by clicking on the "HTML & Javascript" button in the "Share" tab of your typebot.
Here is an example:
<script type="module">
import Typebot from "https://cdn.jsdelivr.net/npm/@typebot.io/js@0/dist/web.js";
Typebot.initPopup({
typebot: "my-typebot",
apiHost: "http://localhost:3001",
autoShowDelay: 3000,
});
</script>
This code will automatically trigger the popup window after 3 seconds.
You can use these commands:
Typebot.open();
Typebot.close();
Typebot.toggle();
You can bind these commands on a button element, for example:
<button onclick="Typebot.open()">Contact us</button>
You can get the bubble HTML and Javascript code by clicking on the "HTML & Javascript" button in the "Share" tab of your typebot.
Here is an example:
<script type="module">
import Typebot from "https://cdn.jsdelivr.net/npm/@typebot.io/js@0/dist/web.js";
Typebot.initBubble({
typebot: "my-typebot",
previewMessage: {
message: "I have a question for you!",
autoShowDelay: 5000,
avatarUrl: "https://avatars.githubusercontent.com/u/16015833?v=4",
},
theme: {
button: { backgroundColor: "#0042DA", iconColor: "#FFFFFF" },
previewMessage: { backgroundColor: "#ffffff", textColor: "black" },
chatWindow: { backgroundColor: "#ffffff" },
},
});
</script>
This code will show the bubble and let a preview message appear after 5 seconds.
You can use these commands:
Typebot.showPreviewMessage();
Typebot.hidePreviewMessage();
You can use these commands:
Typebot.open();
Typebot.close();
Typebot.toggle();
You can bind these commands on a button element, for example:
<button onclick="Typebot.open()">Contact us</button>
You can prefill the bot variable values in your embed code by adding the prefilledVariables
option. Here is an example:
Typebot.initStandard({
typebot: "my-typebot",
prefilledVariables: {
"Current URL": "https://my-site/account",
"User name": "John Doe",
},
});
It will prefill the Current URL
variable with "https://my-site/account" and the User name
variable with "John Doe". More info about variables: here.
Note that if your site URL contains query params (i.e. https://typebot.io?User%20name=John%20Doe), the variables will automatically be injected to the typebot. So you don't need to manually transfer query params to the bot embed configuration.
FAQs
Javascript library to display typebots on your website
The npm package @adrianmaj/typebot-js receives a total of 1 weekly downloads. As such, @adrianmaj/typebot-js popularity was classified as not popular.
We found that @adrianmaj/typebot-js demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Four npm packages disguised as cryptographic tools steal developer credentials and send them to attacker-controlled Telegram infrastructure.
Security News
Ruby maintainers from Bundler and rbenv teams are building rv to bring Python uv's speed and unified tooling approach to Ruby development.
Security News
Following last week’s supply chain attack, Nx published findings on the GitHub Actions exploit and moved npm publishing to Trusted Publishers.