PkgRadar

npm · registry.npmjs.org

@agentai2026/openclaw-zh

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.5.28-zh

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-pWVRAz0d.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-D0gJV2K3.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/i18n-eLAkCRYg.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/extensions/phone-control/index.js
highJs Split Join ObfuscationArray-of-single-tokens joined to form a string — used to obscure module names like require(["n","o","de",":","cr","yp","to"].join("")), defeating static require() analysis. · package/dist/loader-6emNCU1C.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-Cblzlz4I.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-DHRrBEi1.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-BWVRAOIP.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.5.28-zhHigh risk2532026-05-30
2026.5.27-zhHigh risk2532026-05-30
2026.5.27-zh.nightly.5High risk2532026-05-30
2026.5.27-zh.nightly.6High risk2532026-05-30
2026.5.27-zh.nightly.4High risk3332026-05-30
2026.5.30-zh.20260530Low risk02026-05-30
1.0.1Low risk02026-05-29
1.0.0Low risk02026-05-29

Related campaigns

Block this in CI

PkgRadar gates @agentai2026/openclaw-zh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agentai2026/[email protected]