PkgRadar

npm · registry.npmjs.org

@agentium/core

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 2.6.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/index.cjs
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2.6.0High risk602026-06-11
2.5.0High risk602026-06-11
2.4.0High risk602026-06-11
2.3.2High risk602026-06-11
2.3.1High risk602026-06-10
2.2.3Review72026-05-27
2.3.0Review72026-05-27
2.2.2Review72026-05-27
2.1.1Review72026-05-26
2.2.1Review72026-05-26
2.0.6Review72026-05-26
2.0.7Review72026-05-26
2.0.5Review202026-05-25
2.0.3Review202026-05-25
2.0.4Review202026-05-25

Block this in CI

PkgRadar gates @agentium/core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @agentium/[email protected]
@agentium/core — npm security scan | PkgRadar