PkgRadar

Go modules · proxy.golang.org

github.com/qwexvf/aegis-cli

Known Indicator Filename: github.com/qwexvf/[email protected]/examples/incidents/npm/tanstack-router-1.169.5/router_init.js

Why PkgRadar flagged v0.28.0

SeveritySignalEvidence
highKnown Indicator Filenamegithub.com/qwexvf/[email protected]/examples/incidents/npm/tanstack-router-1.169.5/router_init.js · github.com/qwexvf/[email protected]/examples/incidents/npm/tanstack-router-1.169.5/router_init.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · github.com/qwexvf/[email protected]/internal/infra/scan/ast/js/taint.go
highWebhook Exfil Endpointmatched "ngrok-free.app" · github.com/qwexvf/[email protected]/internal/infra/scan/heuristics/source_patterns.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.28.0High risk952026-06-12
v0.29.1High risk952026-06-12

Block this in CI

PkgRadar gates github.com/qwexvf/aegis-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/qwexvf/[email protected]