PkgRadar

npm · registry.npmjs.org

@humanbased/crosscheck

Webhook Exfil Endpoint: matched "smee.io"

Why PkgRadar flagged 0.18.0-beta.7

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "smee.io" · package/dist/commands/onboard.js
highWebhook Exfil Endpointmatched "smee.io" · package/dist/commands/watch.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.18.0-beta.7High risk502026-06-12
0.17.1-beta.2High risk502026-06-12
0.17.1-beta.0High risk502026-06-12
0.17.0High risk502026-06-12
0.16.0High risk502026-06-10
0.16.1-beta.0High risk502026-06-10
0.16.0-beta.34High risk502026-06-10
0.16.0-beta.32High risk502026-06-10
0.16.0-beta.24High risk502026-06-10
0.16.0-beta.16High risk502026-06-10
0.16.0-beta.8High risk502026-06-10
0.16.0-beta.6High risk502026-06-10
0.15.1-beta.3High risk502026-06-10
0.15.0High risk502026-06-10
0.15.1-beta.0High risk502026-06-10
0.15.0-beta.162High risk502026-06-10
0.15.0-beta.157High risk502026-06-10
0.15.0-beta.159High risk502026-06-10
0.15.0-beta.154High risk502026-06-10
0.15.0-beta.147High risk502026-06-10
0.15.0-beta.145High risk502026-06-10
0.14.0High risk502026-06-10
0.15.0-beta.103High risk502026-06-10

Block this in CI

PkgRadar gates @humanbased/crosscheck (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @humanbased/[email protected]