PkgRadar

Cargo · crates.io

revka

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 2026.6.11

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · revka-2026.6.11/src/onboard/wizard.rs
mediumRs Build Time CommandProcess spawn (std::process::Command) at build time. · revka-2026.6.11/build.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/agent/loop_.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/cron/mod.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/cron/scheduler.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/peripherals/arduino_flash.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/peripherals/nucleo_flash.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/security/policy.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/skills/audit.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/skills/mod.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/tools/cron_add.rs
mediumRemote Payloadmatched "curl " · revka-2026.6.11/src/tools/cron_update.rs

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.11High risk1552026-06-12

Block this in CI

PkgRadar gates revka (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem cargo [email protected]
revka — Cargo security scan | PkgRadar