PkgRadar

Go modules · proxy.golang.org

github.com/stormbane-security/beacon

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged v0.1.14

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · github.com/stormbane-security/[email protected]/internal/scanner/takeover/scanner.go
highDNS / OAST exfiltrationmatched "dig AXFR {asset} @$(" · github.com/stormbane-security/[email protected]/internal/report/verify.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/agent/dropper.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/analyze/analyzer.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/chainengine/chains.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/evasion/monitor.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/airflow.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/apache_rce.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/argocd.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/bamboo.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/bitbucket.go
mediumRemote Payloadmatched "curl " · github.com/stormbane-security/[email protected]/internal/postexploit/cacti.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.1.14High risk2702026-06-10
v0.1.15High risk2702026-06-10
v0.1.10High risk2422026-06-10
v0.1.9High risk2422026-06-10
v0.1.13High risk2572026-06-10
v0.1.11High risk2472026-06-10
v0.1.8High risk2422026-06-10
v0.1.5High risk2002026-06-10
v0.1.0High risk1372026-06-10
v0.1.2High risk1472026-06-10
v0.1.6High risk2002026-06-10
v0.1.1High risk1422026-06-10
v0.1.16High risk2702026-06-10
v0.1.3High risk1902026-06-10
v0.1.7High risk2002026-06-10
v0.1.12High risk2472026-06-10
v0.1.4High risk2002026-06-10
v0.1.17High risk2702026-06-10

Block this in CI

PkgRadar gates github.com/stormbane-security/beacon (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/stormbane-security/[email protected]