PkgRadar

npm · registry.npmjs.org

@fedify/fedify

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2.3.0-dev.1336

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/sig/http.test.mjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.3.0-dev.1336High risk122026-06-16
2.3.0-dev.1299High risk122026-06-11
2.3.0-dev.1281High risk122026-06-10
2.3.0-dev.1274High risk122026-06-10
2.3.0-dev.1280High risk122026-06-10
2.3.0-dev.1273Review122026-06-09
2.3.0-dev.1258Review122026-06-07
2.3.0-dev.1219Review122026-06-05
2.2.5Review122026-06-05
2.1.16Review122026-06-05
2.0.20Review122026-06-05
2.3.0-dev.1214Review122026-06-05
2.3.0-dev.1213Review122026-06-04
2.2.4Review122026-06-04
2.3.0-dev.1212Review122026-06-04
2.1.15Review122026-06-04
2.0.19Review122026-06-04
1.10.11Review122026-06-04
1.9.12Review122026-06-04
1.9.12-dev.2265Review122026-06-04
2.3.0-dev.1190Review122026-06-01
2.3.0-dev.1189Review122026-06-01
2.3.0-dev.1184Review122026-05-28
2.3.0-dev.1158Review122026-05-25
2.3.0-dev.1172Review122026-05-25

Block this in CI

PkgRadar gates @fedify/fedify (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @fedify/[email protected]