PkgRadar

npm · registry.npmjs.org

ai-client-sdk

Remote Payload: matched "raw.githubusercontent.com"

Why PkgRadar flagged 4.1.3

SeveritySignalEvidence
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/umd/ai-client-sdk.umd.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/umd/ai-client-sdk.umd.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/es/vendor-ajv-BgE6aqKX.mjs
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/es/vendor-react-dom-Dt3jXKg5.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
5.0.0Low risk02026-06-13
4.3.2Low risk02026-06-06
4.3.1Low risk02026-06-05
4.3.0Low risk02026-06-03
4.2.0Low risk02026-06-01
4.1.6Low risk02026-05-26
4.1.5Low risk02026-05-25
4.1.3Review242026-05-24
4.1.4Review122026-05-24

Block this in CI

PkgRadar gates ai-client-sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]