PkgRadar

Cargo · crates.io

forjar

Webhook Exfil Endpoint: matched "hooks.slack.com/services/"

Why PkgRadar flagged 1.6.2

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "hooks.slack.com/services/" · forjar-1.6.2/src/core/store/tests_falsify_spec_c.rs
highWebhook Exfil Endpointmatched "hooks.slack.com/services/" · forjar-1.6.2/src/core/store/tests_secret_scan.rs
mediumRemote Payloadmatched "github.com/{}/releases/download" · forjar-1.6.2/src/cli/dist_checksums.rs
mediumRemote Payloadmatched "github.com/${{REPO}}/releases/download" · forjar-1.6.2/src/cli/dist_generators.rs
mediumRemote Payloadmatched "github.com/{}/releases/download" · forjar-1.6.2/src/cli/dist_generators_b.rs
mediumRemote Payloadmatched "github.com/{}/releases/download" · forjar-1.6.2/src/cli/dist_homebrew.rs
mediumRemote Payloadmatched "curl " · forjar-1.6.2/src/cli/lint.rs
mediumRemote Payloadmatched "curl " · forjar-1.6.2/src/cli/tests_agent_registry.rs
mediumRemote Payloadmatched "curl " · forjar-1.6.2/src/cli/tests_agent_registry_cov.rs
mediumRemote Payloadmatched "curl\n" · forjar-1.6.2/src/cli/tests_cbom.rs
mediumRemote Payloadmatched "curl\n " · forjar-1.6.2/src/cli/tests_cov_remaining_10_b.rs
mediumRemote Payloadmatched "github.com/acme/tool/releases/download" · forjar-1.6.2/src/cli/tests_dist_verify_tier2.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
1.6.2High risk2252026-06-13
1.6.1High risk2252026-06-13

Block this in CI

PkgRadar gates forjar (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]