PkgRadar

npm · registry.npmjs.org

@kenkaiiii/gg-boss

Remote Payload: matched "api.telegram.org/bot"

Why PkgRadar flagged 4.10.1

SeveritySignalEvidence
mediumRemote Payloadmatched "api.telegram.org/bot" · package/dist/cli.js

Scanned versions

VersionVerdictScoreScanned (UTC)
4.10.1Review112026-06-13
4.10.0Review112026-06-13
4.9.1Review112026-06-13
4.9.0Review112026-06-13
4.8.7Review172026-06-12
4.8.6Review172026-06-12
4.8.5Review172026-06-11
4.8.4Review172026-06-11
4.8.3Review172026-06-11
4.8.2Review172026-06-10
4.8.1Review172026-06-09
4.8.0Review172026-06-09
4.7.0Review172026-06-06
4.6.3Review172026-06-06
4.6.2Review172026-06-04
4.6.1Review172026-06-04
4.6.0Review172026-06-04
4.5.0Review172026-06-04
4.4.0Review172026-06-04
4.3.163Review172026-05-29
4.3.164Review172026-05-29

Block this in CI

PkgRadar gates @kenkaiiii/gg-boss (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm @kenkaiiii/[email protected]