AI chat components and utilities for the Eight Wave Agent Studio platform. The package offers multiple entry points depending on your use case — from a drop-in web component to a framework-agnostic API client.
No malicious attack was identified. The main bundle contains browser telemetry directed to the vendor service, but inspected source did not establish credential collection or an unrelated destination.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package contains a possible secret pattern.
dist/_chunks/index.es-CvfaFCuJ.jsView on unpkg · L30Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L227Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1142Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CN8mivJ9.jsView on unpkgHardcoded password in dist/_chunks/web-CEmtEYdH.js
dist/_chunks/web-CEmtEYdH.jsView on unpkg · L7027This report applies to @8wave/ai-elements@0.114.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Browser source reuses an authenticated session to collect identity data and mutate account settings while reporting externally.
dist-vue/index.jsView on unpkg · L227Package source references dynamic require/import behavior.
dist-vue/index.jsView on unpkg · L1142Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/ai-elements.es.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist-vue/_chunks/dist-Csm5xBQw.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/_chunks/iconify-CN8mivJ9.jsView on unpkgHardcoded password in dist/_chunks/web-CEmtEYdH.js
dist/_chunks/web-CEmtEYdH.jsView on unpkg · L7027Package contains a possible secret pattern.
dist/_chunks/index.es-CvfaFCuJ.jsView on unpkg · L30