PkgRadar

npm · registry.npmjs.org

@anvilwing/vigil

Webhook Exfil Endpoint, New Account With Lifecycle Hook, Credential file access +1 more

Why PkgRadar flagged 2.0.25

SeveritySignalEvidence
highWebhook Exfil Endpointpackage/dist/core/aegis.js
highNew Account With Lifecycle Hookpackage.json

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.25Review552026-06-24
2.0.26Review652026-06-24

Block this in CI

PkgRadar gates @anvilwing/vigil (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @anvilwing/[email protected]