PkgRadar

npm · registry.npmjs.org

@backstage/cli-module-github

Webhook Exfil Endpoint: matched "smee.io"

Why PkgRadar flagged 0.0.0-nightly-20260518032303

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "smee.io" · package/dist/commands/create-github-app/GithubCreateAppServer.cjs.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.0.0-nightly-20260518032303High risk202026-06-12
0.0.0-nightly-20260519032312High risk202026-06-12
0.0.0-nightly-20260612032440High risk202026-06-12
0.1.2High risk202026-06-12

Block this in CI

PkgRadar gates @backstage/cli-module-github (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @backstage/[email protected]