PkgRadar

npm · registry.npmjs.org

@goplus/agentguard

Webhook Exfil Endpoint: matched "webhook.site"

Why PkgRadar flagged 1.1.27

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "webhook.site" · package/dist/action/detectors/network.js
highDNS / OAST exfiltrationmatched "burpcollaborator.net" · package/dist/action/detectors/network.js

Scanned versions

VersionVerdictScoreScanned (UTC)
1.1.27High risk852026-06-13
1.1.28-beta.2High risk632026-06-10
1.1.26High risk852026-06-10
1.1.20High risk592026-06-10
1.1.18High risk592026-06-10
1.1.28-beta.1High risk592026-06-10
1.1.28-beta.0High risk592026-06-10
1.1.14High risk852026-06-10
1.1.21High risk592026-05-28
1.1.16High risk732026-05-25
1.1.15High risk1052026-05-25

Related campaigns

Block this in CI

PkgRadar gates @goplus/agentguard (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @goplus/[email protected]