PkgRadar

npm · registry.npmjs.org

@agentai2027/openclaw-zh

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.6.5-zh

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-C-tiotRe.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-DCG_wTUQ.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/i18n-BSDj5DiS.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-CujWGwKN.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-CSqfL5Dl.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-dL3ZYqX8.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.6.5-zhHigh risk1422026-06-10
2026.4.23-zhHigh risk982026-06-10
2026.4.24-zhHigh risk1012026-06-10
2026.4.25-zhHigh risk1012026-06-10
2026.4.26-zhHigh risk1052026-06-10
2026.4.27-zhHigh risk1052026-06-10
2026.6.1-zhHigh risk1422026-06-10
2026.4.29-zhHigh risk1072026-06-10
2026.5.2-zhHigh risk1142026-06-10
2026.5.4-zhHigh risk862026-06-10
2026.5.5-zhHigh risk862026-06-10
2026.5.6-zhHigh risk862026-06-10
2026.5.7-zhHigh risk862026-06-10
2026.5.12-zhHigh risk1142026-06-10
2026.5.18-zhHigh risk1312026-06-10
2026.5.19-zhHigh risk1382026-06-10
2026.5.20-zhHigh risk1382026-06-10
2026.5.22-zhHigh risk1382026-06-10
2026.5.26-zhHigh risk1382026-06-10
2026.5.27-zhHigh risk1382026-06-10
2026.5.28-zhHigh risk1422026-06-10
2026.5.3-zhReview512026-06-03

Block this in CI

PkgRadar gates @agentai2027/openclaw-zh (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agentai2027/[email protected]