PkgRadar

npm · registry.npmjs.org

@fullstackunicorn/create-root

Webhook Exfil Endpoint: matched "ngrok-free.app"

Why PkgRadar flagged 1.0.26

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/assets/root.fullstackunicorn.dev/frontend/vite.config.js
highCredential File Packagedpackage/assets/root.fullstackunicorn.dev/assets/.env · package/assets/root.fullstackunicorn.dev/assets/.env
highCredential File Packagedpackage/assets/root.fullstackunicorn.dev/backend/.env · package/assets/root.fullstackunicorn.dev/backend/.env
highCredential File Packagedpackage/assets/root.fullstackunicorn.dev/frontend/.env · package/assets/root.fullstackunicorn.dev/frontend/.env
highCredential File Packagedpackage/assets/root.fullstackunicorn.dev/manager/.env · package/assets/root.fullstackunicorn.dev/manager/.env

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.26High risk1452026-06-10
1.0.27High risk1452026-06-10

Related campaigns

Block this in CI

PkgRadar gates @fullstackunicorn/create-root (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @fullstackunicorn/[email protected]
@fullstackunicorn/create-root — npm security scan | PkgRadar