Wanar AI v1.0.5 - Professional AI Chat Platform + CLI Agent by Wisnu Alfian Nur Ashar & Siti Nurfadhila Az Zahra Syam
After a user starts the web server, an unauthenticated local client can invoke filesystem, shell, and active security-scanning tools. No install-time behavior or external credential-exfiltration endpoint was found.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/security-scanner.jsView on unpkg · L5Package contains a possible secret pattern.
src/security-scanner.jsView on unpkg · L1163Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4091Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4120Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4223Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4265Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4311Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4391Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L5368Package source references child process execution.
client/dist/assets/index-Yf8uu-wW.jsView on unpkg · L108Package source references shell execution.
client/dist/assets/index-Yf8uu-wW.jsView on unpkg · L112Source reaches cloud instance metadata or link-local credential endpoints.
src/ai-manager.jsView on unpkg · L81Package source references a known benign dynamic code generation pattern.
src/ai-manager.jsView on unpkg · L321This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/server.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/server.jsView on unpkg · L1497Source combines credential-like environment material and outbound requests; review data flow before blocking.
src/tools/job-agent.jsView on unpkg · L121A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/tools/job-agent.jsView on unpkg · L121Source contains an obfuscated payload loader that reconstructs and executes hidden code.
src/security-scanner.jsView on unpkg · L5Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4091Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4120Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4223Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4265Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4311Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L4391Hardcoded password in src/security-scanner.js
src/security-scanner.jsView on unpkg · L5368Package source references child process execution.
client/dist/assets/index-Yf8uu-wW.jsView on unpkg · L108Package source references shell execution.
client/dist/assets/index-Yf8uu-wW.jsView on unpkg · L112Package contains a possible secret pattern.
src/security-scanner.jsView on unpkg · L1163Source reaches cloud instance metadata or link-local credential endpoints.
src/ai-manager.jsView on unpkg · L81Package source references a known benign dynamic code generation pattern.
src/ai-manager.jsView on unpkg · L321A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/server.jsView on unpkg · L1497This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/server.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
src/tools/job-agent.jsView on unpkg · L121A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
src/tools/job-agent.jsView on unpkg · L121