PkgRadar

npm · registry.npmjs.org

@adcp/sdk

DNS / OAST exfiltration: matched "dns.lookup"

Why PkgRadar flagged 8.1.0-beta.15

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/lib/server/pin-and-bind-fetch.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/lib/testing/storyboard/request-signing/probe.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/lib/net/ssrf-fetch.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/lib/substitution/observer/SubstitutionObserver.js

Scanned versions

VersionVerdictScoreScanned (UTC)
9.0.0-beta.29Low risk02026-06-13
9.0.0-beta.28Low risk02026-06-10
9.0.0-beta.27Low risk02026-06-07
9.0.0-beta.26Low risk02026-06-06
9.0.0-beta.25Low risk02026-06-05
9.0.0-beta.24Low risk02026-06-04
9.0.0-beta.23Low risk02026-06-04
9.0.0-beta.22Low risk02026-06-03
8.1.0-beta.21Low risk02026-06-01
8.1.0-beta.20Low risk02026-06-01
8.1.0-beta.19Low risk02026-05-31
8.1.0-beta.18Low risk02026-05-30
8.1.0-beta.17Low risk02026-05-30
7.11.1Low risk02026-05-30
8.1.0-beta.16Low risk02026-05-29
8.1.0-beta.15Review152026-05-28
8.1.0-beta.14Review152026-05-28
8.1.0-beta.13Review152026-05-26
8.1.0-beta.12Review152026-05-26
8.1.0-beta.11Review152026-05-25
8.1.0-beta.10Review1602026-05-25
8.1.0-beta.9Review1602026-05-24
8.1.0-beta.7Review1602026-05-24
8.1.0-beta.8Review1602026-05-24

Block this in CI

PkgRadar gates @adcp/sdk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @adcp/[email protected]