PkgRadar

npm · registry.npmjs.org

@earendil-works/gondolin

DNS / OAST exfiltration: matched "dns.lookup"

Why PkgRadar flagged 0.11.0

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/src/qemu/http.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/src/http/utils.js
mediumCredential file accessmatched ".ssh" · package/dist/src/ssh/utils.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.11.0Review212026-05-28
0.12.0Review212026-05-28

Block this in CI

PkgRadar gates @earendil-works/gondolin (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @earendil-works/[email protected]