PkgRadar

Go modules · proxy.golang.org

github.com/weppos/publicsuffix-go

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged v0.50.4-0.20260615073152-a3e96f63236c

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · github.com/weppos/[email protected]/publicsuffix/rules.go
mediumRemote Payloadmatched "raw.githubusercontent.com" · github.com/weppos/[email protected]/publicsuffix/generator/gen.go

Scanned versions

VersionVerdictScoreScanned (UTC)
v0.50.4-0.20260615073152-a3e96f63236cHigh risk522026-06-17
v0.0.0-20170403125532-fb1fc944c980Review122026-06-17
v0.50.4-0.20260610151850-50075b7d0013High risk522026-06-11
v0.0.0-20180330102531-4940cc0b6ed2Review122026-06-09
v0.4.1-0.20180525084026-7b797a912719Review122026-06-04
v0.50.4-0.20260529064242-164fc2a0e798High risk522026-05-31

Block this in CI

PkgRadar gates github.com/weppos/publicsuffix-go (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem go github.com/weppos/[email protected]