PkgRadar

npm · registry.npmjs.org

@agenticmail/enterprise

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.5.615

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/chunk-VWIDJRD4.js
highNew Lifecycle Script Vs Previouspostinstall added in 0.5.615 vs 0.5.614: "node scripts/ensure-pm2-startup.cjs --quiet || true" · package.json
highInstall Lifecycle Suppresses Failurepostinstall="node scripts/ensure-pm2-startup.cjs --quiet || true" · package.json
mediumRemote Payloadmatched "curl " · package/bin/agenticmail-enterprise.cjs
mediumRemote Payloadmatched "curl " · package/dist/agent-tools-5LLIXV6A.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/chunk-GC77MDKW.js
mediumRemote Payloadmatched "curl " · package/dist/chunk-IXAWHXMY.js
mediumRemote Payloadmatched "curl " · package/dist/chunk-MVD2DMAY.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/chunk-T26AVIAQ.js
mediumRemote Payloadmatched "raw.githubusercontent.com" · package/dist/chunk-VWIDJRD4.js
mediumRemote Payloadmatched "wget " · package/dist/cli-agent-DOLO7OCU.js
mediumRemote Payloadmatched "curl " · package/dist/cli-recover-OXRLXXCB.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.5.615High risk2462026-06-10
0.5.614High risk1262026-06-10
0.5.613High risk1262026-06-10
0.5.612High risk1262026-06-10
0.5.611High risk1262026-06-10

Campaign attribution

Part of the asteroiddao npm campaign campaign.

Related campaigns

Block this in CI

PkgRadar gates @agenticmail/enterprise (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agenticmail/[email protected]