PkgRadar

npm · registry.npmjs.org

@invarn/cibuild

Webhook Exfil Endpoint: matched "hooks.slack.com/services/"

Why PkgRadar flagged 2.0.4

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "hooks.slack.com/services/" · package/dist/cli.cjs

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.9Review402026-06-17
2.0.8Review242026-06-14
2.0.7Review282026-06-14
2.0.6Review242026-06-14
2.0.5Review282026-06-14
2.0.4High risk562026-06-13
2.0.2Review282026-06-13
2.0.3High risk562026-06-13
2.0.1Review352026-06-11
2.0.0High risk752026-06-10
1.9.9High risk802026-06-10
1.9.8High risk802026-06-10
1.9.6High risk802026-06-10
1.9.3High risk802026-06-10
1.9.7Review402026-06-08
1.9.5Review352026-06-08
1.9.4Review352026-06-07
1.9.1Review422026-05-26
1.9.2Review472026-05-26

Block this in CI

PkgRadar gates @invarn/cibuild (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @invarn/[email protected]