PkgRadar

npm · registry.npmjs.org

@jango-blockchained/hoox-cli

Webhook Exfil Endpoint: matched "api.telegram.org/bot"

Why PkgRadar flagged 0.7.0

SeveritySignalEvidence
highWebhook Exfil Endpointmatched "api.telegram.org/bot" · package/dist/index.js

Scanned versions

VersionVerdictScoreScanned (UTC)
0.7.0High risk402026-06-10
0.5.12High risk402026-06-10
0.5.11High risk402026-06-10
0.5.8High risk402026-06-10
0.5.7High risk402026-06-10
0.5.6High risk402026-06-10
0.5.10High risk402026-06-10
0.5.1Review122026-05-25
0.5.2Review122026-05-25

Block this in CI

PkgRadar gates @jango-blockchained/hoox-cli (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @jango-blockchained/[email protected]