PkgRadar

npm · registry.npmjs.org

@gaodefa/daocore

Webhook Exfil Endpoint: matched "ngrok.app"

Why PkgRadar flagged 2026.5.102

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "ngrok.app" · package/dist/dist-Dh8IiMKH.js
highWebhook Exfil Endpointmatched "ngrok-free.app" · package/dist/guarded-json-api-peOEphyI.js
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/i18n-Bphgsdj4.js
mediumCredential file accessmatched ".npmrc" · package/dist/install-package-dir-DFrWaS4g.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-install-env-BDr63VWf.js
mediumCredential file accessmatched ".npmrc" · package/dist/npm-managed-root-DqR9IP-y.js

Scanned versions

VersionVerdictScoreScanned (UTC)
2026.5.102High risk1982026-06-13
2026.5.101High risk1382026-06-10
2026.5.100High risk1382026-06-10
2026.5.82High risk1382026-06-10
2026.5.83High risk1382026-06-10
2026.5.76High risk1382026-06-10
2026.5.77High risk1382026-06-10
2026.5.75High risk1382026-06-10
2026.5.74High risk1382026-06-10
2026.5.72High risk1382026-06-10
2026.5.73High risk1382026-06-10
2026.5.68High risk1382026-06-10
2026.5.67High risk1382026-06-10
2026.5.65High risk1382026-06-10
2026.5.64High risk1382026-06-10
2026.5.63High risk1382026-06-10
2026.5.62High risk1382026-06-10
2026.5.61High risk1382026-06-10
2026.5.60High risk1382026-06-10
2026.5.59High risk1382026-06-10
2026.5.58High risk1382026-06-10
2026.5.50High risk1382026-06-10
2026.5.51High risk1382026-06-10
2026.5.44High risk1382026-06-10
2026.5.48High risk1382026-06-10
2026.5.42High risk1382026-06-10
2026.5.46High risk1382026-06-10
2026.5.47High risk1382026-06-10
2026.5.41High risk1382026-06-10
2026.5.38High risk1382026-06-10
2026.5.45High risk1382026-06-10
2026.5.34High risk1382026-06-10
2026.5.43High risk1382026-06-10
2026.5.35High risk1382026-06-10
2026.5.37High risk1382026-06-10

Related campaigns

Block this in CI

PkgRadar gates @gaodefa/daocore (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @gaodefa/[email protected]