PkgRadar

npm · registry.npmjs.org

@holon-dev/desk

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.4.2-nightly.202606161117

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/standalone/apps/web/.next/server/chunks/2190.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.4.2-nightly.202606161117High risk282026-06-16
0.4.2-nightly.202606151222High risk282026-06-15
0.4.2-nightly.202606140940High risk282026-06-14
0.4.2-nightly.202606130921High risk402026-06-13
0.4.2-nightly.202606121019High risk402026-06-13
0.4.2-nightly.202606111042High risk402026-06-11
0.4.2-nightly.202606101007High risk402026-06-10
0.4.2-nightly.202606081102High risk402026-06-10
0.4.2-nightly.202606090952High risk402026-06-10
0.4.2-nightly.202606070918High risk402026-06-10
0.4.2-nightly.202606060837High risk402026-06-10
0.4.2-nightly.202606050957High risk402026-06-10
0.4.2-nightly.202606041001High risk402026-06-10
0.4.2-nightly.202606031106High risk402026-06-10
0.4.2-nightly.202606021030High risk402026-06-10
0.4.2-nightly.202606020412High risk402026-06-10
0.4.2-nightly.202606011419High risk402026-06-10
0.4.2-nightly.202606011141High risk402026-06-10
0.4.2High risk402026-06-10
0.4.1-nightly.202606010259High risk402026-06-10
0.4.1High risk402026-06-10

Block this in CI

PkgRadar gates @holon-dev/desk (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @holon-dev/[email protected]