PkgRadar

npm · registry.npmjs.org

@bitseek/claw

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 1.4.3-beta.5

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/extensions/voice-call/src/providers/twilio.test.ts
highWebhook Exfil Endpointmatched "ngrok.app" · package/extensions/voice-call/src/providers/twilio/twiml-policy.test.ts
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/src/webhook-security.test.ts
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/extensions/voice-call/src/webhook-security.ts
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/api-CRdLvaOQ.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/api-CzfBiQzt.js
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/plugin-sdk/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.4.3-beta.5High risk1862026-06-10
1.4.3-beta.6High risk1862026-06-10
1.4.3-beta.4High risk1862026-06-10
1.4.3-beta.3High risk1862026-06-10
1.4.3-beta.1High risk1862026-06-10
1.4.3-beta.2High risk1862026-06-10

Block this in CI

PkgRadar gates @bitseek/claw (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @bitseek/[email protected]
@bitseek/claw — npm security scan | PkgRadar