PkgRadar

Go modules · proxy.golang.org

github.com/ra000wl/syck

Webhook Exfil Endpoint: matched "hooks.slack.com/services/"

Why PkgRadar flagged v1.0.1-0.20260606171932-decbda15aec7

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "hooks.slack.com/services/" · github.com/ra000wl/[email protected]/internal/ruletest/generate.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v1.0.1-0.20260606171932-decbda15aec7High risk582026-06-07
v1.0.0High risk582026-06-07
v0.0.0-20260606105846-29d5c9b2a791High risk582026-06-07
v0.0.0-20260606122818-fb49e34c4a6bHigh risk582026-06-07
v0.0.0-20260606121736-9e9ec2cf54c5High risk582026-06-07
v0.0.0-20260606115115-29de6aaf06a1High risk582026-06-07
v0.0.0-20260606112159-222c342a3bdfHigh risk582026-06-07
v0.0.0-20260605153306-3032f4807c5dReview132026-06-07
v0.0.0-20260606103742-049e788f88f0High risk582026-06-07
v0.0.0-20260606081643-cb2b9fcd81e7High risk582026-06-07

Block this in CI

PkgRadar gates github.com/ra000wl/syck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/ra000wl/[email protected]