PkgRadar

Cargo · crates.io

forensicnomicon

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 0.2.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · forensicnomicon-0.2.0/src/abusable_sites.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · forensicnomicon-0.2.0/src/catalog/containers_parsing.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · forensicnomicon-0.2.0/src/catalog/descriptors/generated/regedit_generated.rs
mediumRemote Payloadmatched "raw.githubusercontent.com" · forensicnomicon-0.2.0/src/catalog/descriptors/mod.rs
mediumRemote Payloadmatched "wget " · forensicnomicon-0.2.0/src/commands.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
0.2.0High risk932026-06-05

Block this in CI

PkgRadar gates forensicnomicon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]