PkgRadar

npm · registry.npmjs.org

@gakr-gakr/autobot

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 0.1.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-8LASmT1Y.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-vVCgGKts.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/fetch-DxVVai_w.js
highDNS / OAST exfiltrationmatched "dns.lookup" · package/dist/provider-CxWE2uui.js
mediumObfuscation Densityhigh encoded/escaped-token density · package/dist/crypto-runtime-B-eP01Rh.js
mediumRemote Payloadmatched "curl " · package/skills/openai-whisper-api/scripts/transcribe.sh
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-BdTJ6veU.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-DLHFd1ZY.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-Cb2-5NYd.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.1.0High risk2642026-05-25

Related campaigns

Block this in CI

PkgRadar gates @gakr-gakr/autobot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gakr-gakr/[email protected]
@gakr-gakr/autobot — npm security scan | PkgRadar